PT-2022-22863 · Zammad · Zammad
Erik Kipka
+1
·
Published
2022-08-08
·
Updated
2022-08-12
·
CVE-2022-35487
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zammad version 5.2.0
Description
The issue is related to Incorrect Access Control in Zammad, where the software did not correctly perform authorization on certain attachment endpoints. This could be exploited by an unauthenticated attacker to gain access to attachments, such as emails or attached files.
Recommendations
For Zammad version 5.2.0, update to a version that correctly performs authorization on attachment endpoints to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad