CVE-2022-27332
- EPSS 1.05%
- Veröffentlicht 27.04.2022 03:15:39
- Zuletzt bearbeitet 21.11.2024 06:55:35
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
CVE-2022-29700
- EPSS 0.95%
- Veröffentlicht 27.04.2022 03:15:39
- Zuletzt bearbeitet 21.11.2024 06:59:35
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
CVE-2022-29701
- EPSS 1%
- Veröffentlicht 27.04.2022 03:15:39
- Zuletzt bearbeitet 21.11.2024 06:59:35
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messa...
CVE-2021-43145
- EPSS 0.95%
- Veröffentlicht 04.02.2022 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:28:43
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
CVE-2021-44886
- EPSS 0.88%
- Veröffentlicht 04.02.2022 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:31:39
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
CVE-2021-42137
- EPSS 0.84%
- Veröffentlicht 11.10.2021 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:27:20
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
CVE-2021-42084
- EPSS 0.93%
- Veröffentlicht 07.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:13
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.
CVE-2021-42085
- EPSS 0.52%
- Veröffentlicht 07.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:13
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
CVE-2021-42086
- EPSS 1.11%
- Veröffentlicht 07.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:13
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
CVE-2021-42087
- EPSS 0.88%
- Veröffentlicht 07.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:13
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.