CVE-2022-48023: Medium severity zammad vulnerability
Published Feb 3, 2023
·Updated
Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.
Affected Software
1 affected component
Zammad Zammad=5.3.0
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-48023.
2
What is the affected software?
The affected software is Zammad v5.3.0.
3
How can an attacker exploit this vulnerability?
An authenticated attacker can perform changes on the tags of their customer tickets using the Zammad API.
4
How severe is this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 4.3.
5
Is there a fix for this vulnerability?
Yes, the vulnerability has been fixed in Zammad v5.3.1.