CVE-2020-1769 Information
Feb 14, 2021
cve
Description
In the login screens (in agent and customer interface) Username and Password fields use autocomplete which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html https://otrs.com/release-notes/otrs-security-advisory-2020-06/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: