PT-2017-16883 · Zammad · Zammad

Published

2017-03-13

·

Updated

2019-10-03

·

CVE-2017-6080

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 1.0.4 Zammad versions 1.1.x prior to 1.1.3 Zammad versions 1.2.x prior to 1.2.1
Description The issue is caused by a lack of protection mechanism involving HTTP Access-Control headers. An attacker can exploit this by sending cross-domain requests directly to the REST API for users with a valid session cookie and receive the result.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later. For versions 1.1.x prior to 1.1.3, update to version 1.1.3 or later. For versions 1.2.x prior to 1.2.1, update to version 1.2.1 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6080

Affected Products

Zammad