CVE-2017-5619: Zammad
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
Affected products
- Zammad Zammad: up to and including 1.0.3; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.2.0 only
Published 2017-03-13. Last modified 2026-06-17.