It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s),…
OTRS·CWE-155·Published 2020-03-27