CVE-2021-35302: Medium severity zammad vulnerability
Published Jun 28, 2021
·Updated
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=4.0.0
Event History
Jun 28, 2021
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Zammad vulnerability?
The vulnerability ID for this Zammad vulnerability is CVE-2021-35302.
2
What is the severity level of CVE-2021-35302?
The severity level of CVE-2021-35302 is medium with a CVSS score of 5.3.
3
How does CVE-2021-35302 affect Zammad?
CVE-2021-35302 allows remote attackers to obtain sensitive information by exploiting an incorrect access control for linked tickets in Zammad 1.0.x up to 4.0.0.
4
What software versions are affected by CVE-2021-35302?
Zammad versions 1.0.x up to 4.0.0 are affected by CVE-2021-35302.
5
How can the vulnerability in Zammad be fixed?
To fix the vulnerability in Zammad, upgrade to a version higher than 4.0.0.