CVE-2014-1682

Publication date

2014-05-08 14:00:00

Family

mitre

State

PUBLISHED

Description

The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.