Vulnerabilities > CVE-2021-44886 - Unspecified vulnerability in Zammad 5.0.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |