CVE-2020-10096
HIGHZammad 3.0-3.2 - Unauthenticated Exposure of Sensitive Information via Browser Cache
Title source: llmDescription
An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either remotely compromises or obtains physical access to a user's workstation can browse the browser cache contents and obtain sensitive information. The attacker does not need to be authenticated with the application to view this information, as it would be available via the browser cache.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://zammad.com/news/security-advisory-zaa-2020-11
Scores
CVSS v3
7.5
EPSS
0.0114
EPSS Percentile
62.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
zammad/zammad
1.0.0 - 3.2.0
Published
Mar 05, 2020
Tracked Since
Feb 18, 2026