PT-2022-22863 · Zammad · Zammad

Erik Kipka

+1

·

Published

2022-08-08

·

Updated

2022-08-12

·

CVE-2022-35487

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zammad version 5.2.0
Description The issue is related to Incorrect Access Control in Zammad, where the software did not correctly perform authorization on certain attachment endpoints. This could be exploited by an unauthenticated attacker to gain access to attachments, such as emails or attached files.
Recommendations For Zammad version 5.2.0, update to a version that correctly performs authorization on attachment endpoints to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-35487

Affected Products

Zammad