Vulnerabilities > Zammad
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-18 | CVE-2023-31597 | Incorrect Authorization vulnerability in Zammad An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. | 6.5 |
2023-05-02 | CVE-2023-29867 | Unspecified vulnerability in Zammad 5.3.0/5.3.1 Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. | 6.5 |
2023-05-02 | CVE-2023-29868 | Unspecified vulnerability in Zammad 5.3.0/5.3.1 Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. | 6.5 |
2023-02-03 | CVE-2022-48021 | Unspecified vulnerability in Zammad 5.3.0 A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server. | 9.8 |
2023-02-03 | CVE-2022-48022 | Unspecified vulnerability in Zammad 5.3.0 An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see. | 4.3 |
2023-02-03 | CVE-2022-48023 | Unspecified vulnerability in Zammad 5.3.0 Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. | 4.3 |
2022-09-27 | CVE-2022-40816 | Exposure of Resource to Wrong Sphere vulnerability in Zammad 5.2.0/5.2.1 Zammad 5.2.1 is vulnerable to Incorrect Access Control. | 6.5 |
2022-09-27 | CVE-2022-40817 | Incorrect Permission Assignment for Critical Resource vulnerability in Zammad 5.2.0/5.2.1 Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. | 4.3 |
2022-04-27 | CVE-2022-27331 | Exposure of Resource to Wrong Sphere vulnerability in Zammad An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users. | 4.0 |
2022-04-27 | CVE-2022-27332 | Exposure of Resource to Wrong Sphere vulnerability in Zammad An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. | 5.8 |