First published: Wed Apr 27 2022(Updated: )
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | <5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27332 is an access control issue in Zammad v5.0.3 that allows attackers to write entries to the CTI caller log without authentication.
CVE-2022-27332 has a severity rating of 9.1 (critical).
CVE-2022-27332 affects Zammad v5.0.3 and earlier versions up to and excluding v5.1.0.
CVE-2022-27332 can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
To fix CVE-2022-27332, update Zammad to version 5.1.0 or newer.