Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
References
Link | Resource |
---|---|
https://zammad.com/en/advisories/zaa-2023-01 | Vendor Advisory |
https://zammad.com/en/advisories/zaa-2023-01 | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://zammad.com/en/advisories/zaa-2023-01 - Vendor Advisory |
Information
Published : 2023-05-02 16:15
Updated : 2024-11-21 07:57
NVD link : CVE-2023-29868
Mitre link : CVE-2023-29868
CVE.ORG link : CVE-2023-29868
JSON object : View
Products Affected
zammad
- zammad
CWE