Show filters
71 Total Results
Displaying 21-30 of 71
Sort by:
Attacker Value
Unknown

CVE-2022-27331

Disclosure Date: April 27, 2022 (last updated October 07, 2023)
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
Attacker Value
Unknown

CVE-2021-44886

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
Attacker Value
Unknown

CVE-2021-43145

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
Attacker Value
Unknown

CVE-2021-42137

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
Attacker Value
Unknown

CVE-2021-42089

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
Attacker Value
Unknown

CVE-2021-42091

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
Attacker Value
Unknown

CVE-2021-42087

Disclosure Date: October 07, 2021 (last updated November 28, 2024)
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
Attacker Value
Unknown

CVE-2021-42084

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.
Attacker Value
Unknown

CVE-2021-42086

Disclosure Date: October 07, 2021 (last updated November 28, 2024)
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
Attacker Value
Unknown

CVE-2021-42090

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.