First published: Mon Aug 08 2022(Updated: )
Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abused by an unauthenticated attacker to gain access to attachments, such as emails or attached files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | =5.2.0 | |
Zammad Zammad | =5.2.0-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-35487.
The severity of CVE-2022-35487 is high.
Zammad version 5.2.0 and 5.2.0-alpha are affected.
This vulnerability allows an unauthenticated attacker to gain access to attachments, such as emails or attached files.
Currently, there is no information available about a fix for CVE-2022-35487. It is recommended to follow the security advisory from Zammad for updates.