CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. See the original NVD description below for full technical details.
CVE
CVE-2020-26034
Severity
MEDIUM
CVSS
4.3
EPSS
0.72%
Original NVD Description
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)