CVE-2020-26028: Medium severity zammad vulnerability
Published Dec 28, 2020
·Updated
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket. permission can access Tickets.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<3.4.1
Event History
Dec 28, 2020
CVE Published
via MITRE·07:57 AM
Data Sourced
via MITRE·07:57 AM
Description
Frequently Asked Questions
1
What is the ID of the vulnerability in Zammad?
The ID of the vulnerability in Zammad is CVE-2020-26028.
2
What is the severity of CVE-2020-26028?
The severity of CVE-2020-26028 is medium (4.9).
3
What is the description of CVE-2020-26028?
CVE-2020-26028 is an issue in Zammad before 3.4.1 where admin users without a ticket.* permission can access tickets.
4
How can the vulnerability in Zammad be fixed?
To fix the vulnerability in Zammad, it is recommended to update to version 3.4.1 or higher.
5
Where can I find more information about CVE-2020-26028?
More information about CVE-2020-26028 can be found at the following link: https://zammad.com/news/security-advisory-zaa-2020-19