CVE-2020-26032: SSRF
Published Dec 28, 2020
·Updated
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the server. This may lead to disclosure of information from intranet systems.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<3.4.1
Event History
Dec 28, 2020
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26032?
CVE-2020-26032 is an SSRF issue discovered in Zammad before version 3.4.1.
2
What is the severity of CVE-2020-26032?
The severity of CVE-2020-26032 is high with a CVSS score of 7.5.
3
How does CVE-2020-26032 affect Zammad?
CVE-2020-26032 affects Zammad versions 1.0.0 to 3.4.1.
4
How can CVE-2020-26032 be exploited?
An attacker can exploit CVE-2020-26032 by using the SMS configuration interface in Zammad to send a GET request to any URL.
5
How can CVE-2020-26032 be fixed?
To fix CVE-2020-26032, upgrade Zammad to version 3.4.1 or later.