Show filters
71 Total Results
Displaying 21-30 of 71
Sort by:
Attacker Value
Unknown
CVE-2022-27331
Disclosure Date: April 27, 2022 (last updated October 07, 2023)
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
0
Attacker Value
Unknown
CVE-2021-44886
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
0
Attacker Value
Unknown
CVE-2021-43145
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
0
Attacker Value
Unknown
CVE-2021-42137
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
0
Attacker Value
Unknown
CVE-2021-42089
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
0
Attacker Value
Unknown
CVE-2021-42091
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
0
Attacker Value
Unknown
CVE-2021-42087
Disclosure Date: October 07, 2021 (last updated November 28, 2024)
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
0
Attacker Value
Unknown
CVE-2021-42084
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.
0
Attacker Value
Unknown
CVE-2021-42086
Disclosure Date: October 07, 2021 (last updated November 28, 2024)
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
0
Attacker Value
Unknown
CVE-2021-42090
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
0