Zammad

Zammad

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.47%
  • Veröffentlicht 28.06.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:11

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.

  • EPSS 1.07%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:04

An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from t...

  • EPSS 0.85%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:03

An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.

  • EPSS 0.78%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:03

An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of header.

  • EPSS 1.33%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:03

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions i...

  • EPSS 0.63%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:04

An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).

  • EPSS 0.36%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:04

An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.

  • EPSS 0.72%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:04

An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on wheth...

  • EPSS 0.54%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:04

An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.

  • EPSS 0.67%
  • Veröffentlicht 28.12.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:23:44

An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.