CVE-2021-42084
- EPSS 0.43%
- Veröffentlicht 07.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:13
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.
CVE-2021-42094
- EPSS 3.18%
- Veröffentlicht 07.10.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:14
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
CVE-2021-42093
- EPSS 1.07%
- Veröffentlicht 07.10.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:14
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.
CVE-2021-42092
- EPSS 0.5%
- Veröffentlicht 07.10.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:14
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
CVE-2021-35303
- EPSS 0.21%
- Veröffentlicht 28.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:12
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.
CVE-2021-35302
- EPSS 0.21%
- Veröffentlicht 28.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:12
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
CVE-2021-35301
- EPSS 0.21%
- Veröffentlicht 28.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:12
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
CVE-2021-35300
- EPSS 0.22%
- Veröffentlicht 28.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:12
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
CVE-2021-35299
- EPSS 0.32%
- Veröffentlicht 28.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:11
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
CVE-2021-35298
- EPSS 0.21%
- Veröffentlicht 28.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:11
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.