CVE-2022-27332: Critical severity zammad vulnerability
Published Apr 27, 2022
·Updated
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
Affected Software
1 affected component
Zammad Zammad<5.1.0
Remediation
Patch Available
Event History
Apr 27, 2022
CVE Published
via MITRE·02:47 AM
Data Sourced
via MITRE·02:47 AM
Description
Frequently Asked Questions
1
What is CVE-2022-27332?
CVE-2022-27332 is an access control issue in Zammad v5.0.3 that allows attackers to write entries to the CTI caller log without authentication.
2
What is the severity of CVE-2022-27332?
CVE-2022-27332 has a severity rating of 9.1 (critical).
3
How does CVE-2022-27332 affect Zammad?
CVE-2022-27332 affects Zammad v5.0.3 and earlier versions up to and excluding v5.1.0.
4
What are the potential consequences of CVE-2022-27332?
CVE-2022-27332 can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
5
How can I fix CVE-2022-27332 in Zammad?
To fix CVE-2022-27332, update Zammad to version 5.1.0 or newer.