Zammad

Zammad

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 26.04.2024 01:15:46
  • Zuletzt bearbeitet 15.04.2025 16:39:26

An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.

  • EPSS 0.44%
  • Veröffentlicht 26.04.2024 01:15:46
  • Zuletzt bearbeitet 16.09.2026 20:17:20

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

  • EPSS 0.5%
  • Veröffentlicht 10.12.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:01

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to ...

  • EPSS 0.28%
  • Veröffentlicht 10.12.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:01

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.

  • EPSS 0.7%
  • Veröffentlicht 10.12.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:01

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also...

  • EPSS 0.44%
  • Veröffentlicht 10.12.2023 19:15:07
  • Zuletzt bearbeitet 27.05.2025 16:15:30

An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.

  • EPSS 0.42%
  • Veröffentlicht 10.12.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:02

An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.

  • EPSS 0.43%
  • Veröffentlicht 18.05.2023 18:15:10
  • Zuletzt bearbeitet 22.01.2025 15:15:08

An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. Attackers are also able to gain unauthorized access to existing tickets.

  • EPSS 0.45%
  • Veröffentlicht 02.05.2023 16:15:08
  • Zuletzt bearbeitet 30.01.2025 17:15:15

Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.

  • EPSS 1.04%
  • Veröffentlicht 02.05.2023 16:15:08
  • Zuletzt bearbeitet 30.01.2025 17:15:15

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.