First published: Thu Oct 07 2021(Updated: )
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | <4.1.1 | |
<4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-42090.
The severity of CVE-2021-42090 is critical with a score of 9.8.
The affected software is Zammad before version 4.1.1.
The CWE ID for this vulnerability is 502.
This vulnerability can be exploited through the mishandling of deserialization in the Form functionality of Zammad.