ZeroHour

CVE-2022-48023

CVSS 3.1
4.3 medium
EPSS
<1%p38
Published
()
Modified
Description

Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.

Vendors
zammad
Products
zammad
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.