CVE-2021-42090: Critical severity Zammad Zammad vulnerability
Published Oct 7, 2021
·Updated
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
Affected Software
1 affected component
Zammad Zammad<4.1.1
Event History
Oct 7, 2021
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-42090.
2
What is the severity of CVE-2021-42090?
The severity of CVE-2021-42090 is critical with a score of 9.8.
3
What is the affected software?
The affected software is Zammad before version 4.1.1.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 502.
5
How can this vulnerability be exploited?
This vulnerability can be exploited through the mishandling of deserialization in the Form functionality of Zammad.