Vulnerabilities > Zammad > Zammad > 5.2.0

DATE CVE VULNERABILITY TITLE RISK
2023-05-18 CVE-2023-31597 Incorrect Authorization vulnerability in Zammad
An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user.
network
low complexity
zammad CWE-863
6.5
2022-09-27 CVE-2022-40816 Incorrect Authorization vulnerability in Zammad 5.2.0/5.2.1
Zammad 5.2.1 is vulnerable to Incorrect Access Control.
network
low complexity
zammad CWE-863
6.5
2022-09-27 CVE-2022-40817 Incorrect Permission Assignment for Critical Resource vulnerability in Zammad 5.2.0/5.2.1
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets.
network
low complexity
zammad CWE-732
4.3
2022-08-08 CVE-2022-35488 Unspecified vulnerability in Zammad 5.2.0
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
network
low complexity
zammad
7.5
2022-08-08 CVE-2022-35489 Unspecified vulnerability in Zammad 5.2.0
In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.
network
low complexity
zammad
6.5