First published: Mon Dec 28 2020(Updated: )
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the server. This may lead to disclosure of information from intranet systems.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | >=1.0.0<3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26032 is an SSRF issue discovered in Zammad before version 3.4.1.
The severity of CVE-2020-26032 is high with a CVSS score of 7.5.
CVE-2020-26032 affects Zammad versions 1.0.0 to 3.4.1.
An attacker can exploit CVE-2020-26032 by using the SMS configuration interface in Zammad to send a GET request to any URL.
To fix CVE-2020-26032, upgrade Zammad to version 3.4.1 or later.