ZeroHour

CVE-2023-29867

CVSS 3.1
6.5 medium
EPSS
<1%p38
Published
()
Modified
Description

Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.

Vendors
zammad
Products
zammad
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.