Zammad

Zammad

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.65%
  • Veröffentlicht 07.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:13

An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.

  • EPSS 1.1%
  • Veröffentlicht 07.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:14

An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.

  • EPSS 2.33%
  • Veröffentlicht 07.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:14

An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

  • EPSS 1.08%
  • Veröffentlicht 07.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:14

An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

  • EPSS 0.52%
  • Veröffentlicht 07.10.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:14

An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.

  • EPSS 1.3%
  • Veröffentlicht 07.10.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:14

An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.

  • EPSS 1.89%
  • Veröffentlicht 07.10.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:14

An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

  • EPSS 0.89%
  • Veröffentlicht 28.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:12

Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.

  • EPSS 1.2%
  • Veröffentlicht 28.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:12

Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.

  • EPSS 1.2%
  • Veröffentlicht 28.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:12

Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.