CVE-2023-29867: Medium severity zammad vulnerability
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29867.
What is the title of the vulnerability?
The title of the vulnerability is 'Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control.'
What is the severity of CVE-2023-29867?
The severity of CVE-2023-29867 is medium with a CVSS score of 6.5.
What is the affected software version?
The affected software version is Zammad 5.3.x (up to and including 5.3.0) and it is fixed in version 5.4.0.
How can an attacker exploit this vulnerability?
An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
Where can I find more information about CVE-2023-29867?
You can find more information about CVE-2023-29867 in the advisory at https://zammad.com/en/advisories/zaa-2023-02.