PT-2023-22456 · Zammad · Zammad

Published

2023-05-02

·

Updated

2025-01-30

·

CVE-2023-29868

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zammad versions 5.3.x through 5.3.x
Description The issue allows an authenticated attacker with agent and customer roles to perform unauthorized changes on articles where they only have customer permissions, due to incorrect access control.
Recommendations For Zammad versions 5.3.x, update to version 5.4.0 to resolve the issue.

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2023-29868

Affected Products

Zammad