Sensitive User Configuration Data Leakage in Zammad Login Screen

Sensitive User Configuration Data Leakage in Zammad Login Screen

CVE-2023-50453 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

Learn more about our Api Penetration Testing.