ZeroHour

CVE-2022-27331

CVSS 3.1
4.3 medium
EPSS
<1%p51
Published
()
Modified
Description

An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.

Vendors
zammad
Products
zammad
Weakness
CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.