CVE-2020-26029
- EPSS 0.22%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:03
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of header.
CVE-2020-26028
- EPSS 0.26%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:03
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
CVE-2020-26030
- EPSS 0.49%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:03
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions i...
CVE-2020-26031
- EPSS 0.13%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:04
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
CVE-2020-26032
- EPSS 0.28%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:04
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from t...
CVE-2020-26033
- EPSS 0.13%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:04
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
CVE-2020-26035
- EPSS 0.34%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:19:04
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
CVE-2020-29158
- EPSS 0.11%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:23:44
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
CVE-2020-29159
- EPSS 0.34%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:23:45
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
CVE-2020-29160
- EPSS 0.2%
- Published 28.12.2020 08:15:11
- Last modified 21.11.2024 05:23:45
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.