Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.1
CVE-2017-5621
- EPSS 0.67%
- Veröffentlicht 13.03.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.
9.8
CVE-2017-6080
- EPSS 0.73%
- Veröffentlicht 13.03.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain requests direc...
8.8
CVE-2017-6081
- EPSS 0.59%
- Veröffentlicht 13.03.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.