First published: Mon Jun 28 2021(Updated: )
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | >=1.0.0<=4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security vulnerability is CVE-2021-35299.
The title of this vulnerability is 'Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.'
The severity of CVE-2021-35299 is high with a severity value of 7.5.
CVE-2021-35299 allows attackers to obtain sensitive information through email connection configuration probing in Zammad 1.0.x up to 4.0.0.
Yes, the fix for CVE-2021-35299 can be found in the advisory at https://zammad.com/en/advisories/zaa-2021-02.