Zammad

Zammad

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 08.04.2026 18:02:16
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostnam...

  • EPSS 0.15%
  • Veröffentlicht 08.04.2026 18:01:20
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database...

  • EPSS 0.19%
  • Veröffentlicht 08.04.2026 18:00:09
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for ...

  • EPSS 0.25%
  • Veröffentlicht 05.04.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2025 16:37:00

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

  • EPSS 0.26%
  • Veröffentlicht 05.04.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2025 16:36:06

In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions are met. If a webhook endpoint returned a redirect response, Zammad would follow it au...

  • EPSS 0.28%
  • Veröffentlicht 05.04.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2025 15:31:20

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in...

  • EPSS 0.24%
  • Veröffentlicht 05.04.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2025 15:25:12

In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser cons...

  • EPSS 0.29%
  • Veröffentlicht 09.12.2024 03:15:04
  • Zuletzt bearbeitet 15.04.2025 16:37:30

Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

  • EPSS 0.2%
  • Veröffentlicht 19.05.2024 20:15:08
  • Zuletzt bearbeitet 15.04.2025 16:38:03

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environm...

  • EPSS 0.51%
  • Veröffentlicht 26.04.2024 01:15:46
  • Zuletzt bearbeitet 15.04.2025 16:40:08

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.