Show filters
71 Total Results
Displaying 31-40 of 71
Sort by:
Attacker Value
Unknown

CVE-2021-42085

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
Attacker Value
Unknown

CVE-2021-42088

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.
Attacker Value
Unknown

CVE-2021-42093

Disclosure Date: October 07, 2021 (last updated November 28, 2024)
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.
Attacker Value
Unknown

CVE-2021-42092

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
Attacker Value
Unknown

CVE-2021-42094

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
Attacker Value
Unknown

CVE-2021-35299

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
Attacker Value
Unknown

CVE-2021-35301

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
Attacker Value
Unknown

CVE-2021-35302

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
Attacker Value
Unknown

CVE-2021-35298

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
Attacker Value
Unknown

CVE-2021-35303

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.