CVE-2020-1769AG Community Edition vulnerability

CWE-165 documents5 sources
Severity
4.3MEDIUMNVD
CNA3.5
EPSS
0.7%
top 28.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 24

Description

In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5otrs_ag/community_edition5.0.x5.0.41+1
NVDotrs/otrs5.0.05.0.41+2
CVEListV5otrs_ag/otrs7.0.x7.0.15
NVDopensuse/leap15.1, 15.2+1

🔴Vulnerability Details

3
GHSA
GHSA-xfh6-pvv6-h7qg: In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue2022-05-24
OSV
CVE-2020-1769: In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue2020-03-27
CVEList
Autocomplete in the form login screens2020-03-27

📋Vendor Advisories

1
Debian
CVE-2020-1769: otrs2 - In the login screens (in agent and customer interface), Username and Password fi...2020
CVE-2020-1769 — Otrs AG Community Edition vulnerability | cvebase