CVE-2022-48021: Critical severity zammad vulnerability
Published Feb 3, 2023
·Updated
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.
Affected Software
1 affected component
Zammad Zammad=5.3.0
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-48021.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges'.
3
What is the severity of CVE-2022-48021?
The severity of CVE-2022-48021 is critical with a severity value of 9.8.
4
How does CVE-2022-48021 impact Zammad v5.3.0?
CVE-2022-48021 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server in Zammad v5.3.0.
5
How can I fix CVE-2022-48021?
To fix CVE-2022-48021, it is recommended to update Zammad to a version that is not affected by this vulnerability and follow the guidance provided by the vendor.