An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting…
OTRS·CWE-331·Published 2020-03-27