Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Heiko Stämmler

Researcher fromHeista GmbH
#47491of 53,635
5.3Total CVSS
Vulnerabilities · 1
PT-2022-12252
5.3
2022-02-04
Zammad · Zammad · CVE-2021-44886
**Name of the Vulnerable Software and Affected Versions** Zammad version 5.0.2 **Description** The issue allows agents to configure "out of office" periods and substitute persons. If the substitute persons do not have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to. **Recommendations** For Zammad version 5.0.2, ensure that substitute persons have the same permissions as the original agent to prevent unauthorized access to ticket notifications. As a temporary workaround, consider restricting access to ticket notifications for substitute persons until a proper permission alignment can be established.