Vulnerabilities > Zammad
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-03 | CVE-2022-48023 | Unspecified vulnerability in Zammad 5.3.0 Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. | 4.3 |
2022-09-27 | CVE-2022-40816 | Incorrect Authorization vulnerability in Zammad 5.2.0/5.2.1 Zammad 5.2.1 is vulnerable to Incorrect Access Control. | 6.5 |
2022-09-27 | CVE-2022-40817 | Incorrect Permission Assignment for Critical Resource vulnerability in Zammad 5.2.0/5.2.1 Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. | 4.3 |
2022-08-08 | CVE-2022-35487 | Incorrect Authorization vulnerability in Zammad 5.2.0 Zammad 5.2.0 suffers from Incorrect Access Control. | 7.5 |
2022-08-08 | CVE-2022-35488 | Unspecified vulnerability in Zammad 5.2.0 In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim. | 7.5 |
2022-08-08 | CVE-2022-35489 | Unspecified vulnerability in Zammad 5.2.0 In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned. | 6.5 |
2022-08-08 | CVE-2022-35490 | Improper Restriction of Excessive Authentication Attempts vulnerability in Zammad 5.2.0 Zammad 5.2.0 is vulnerable to privilege escalation. | 9.8 |
2022-04-27 | CVE-2022-27331 | Exposure of Resource to Wrong Sphere vulnerability in Zammad An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users. | 4.3 |
2022-04-27 | CVE-2022-27332 | Missing Authentication for Critical Function vulnerability in Zammad An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. | 9.1 |
2022-04-27 | CVE-2022-29700 | Weak Password Requirements vulnerability in Zammad 5.1.0 A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification. | 7.5 |