CVE-2023-29868: Medium severity zammad vulnerability
Published May 2, 2023
·Updated
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
Affected Software
1 affected component
Zammad Zammad>=5.3.0<5.4.0
Event History
May 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
04:15 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29868?
CVE-2023-29868 is a vulnerability in Zammad 5.3.x that allows an authenticated attacker with agent and customer roles to make unauthorized changes on articles where they only have customer permissions.
2
How can an attacker exploit CVE-2023-29868?
An attacker with both agent and customer roles can exploit CVE-2023-29868 by performing unauthorized changes on articles.
3
What is the severity of CVE-2023-29868?
CVE-2023-29868 has a severity level of medium.
4
What is the affected software for CVE-2023-29868?
The affected software for CVE-2023-29868 is Zammad version 5.3.x (Fixed in 5.4.0).
5
How do I fix CVE-2023-29868?
To fix CVE-2023-29868, update Zammad to version 5.4.0 or later.