First published: Tue May 02 2023(Updated: )
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | >=5.3.0<5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-29867.
The title of the vulnerability is 'Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control.'
The severity of CVE-2023-29867 is medium with a CVSS score of 6.5.
The affected software version is Zammad 5.3.x (up to and including 5.3.0) and it is fixed in version 5.4.0.
An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
You can find more information about CVE-2023-29867 in the advisory at https://zammad.com/en/advisories/zaa-2023-02.