CVE-2023-50456: Medium severity zammad vulnerability
Published Dec 10, 2023
·Updated
An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
Affected Software
3 affected components
Zammad Zammad=6.1.0
Zammad Zammad=6.1.0-alpha
Zammad Zammad=6.2.0-alpha
Event History
Dec 10, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-50456?
The severity of CVE-2023-50456 is classified as high due to its potential for phishing attacks.
2
How do I fix CVE-2023-50456?
To fix CVE-2023-50456, upgrade Zammad to version 6.2.0 or later.
3
Who is affected by CVE-2023-50456?
CVE-2023-50456 affects Zammad versions 6.1.0 and 6.1.0-alpha, as well as 6.2.0-alpha.
4
What type of attack is CVE-2023-50456 associated with?
CVE-2023-50456 is associated with phishing attacks through crafted names in notification emails.
5
Is CVE-2023-50456 being actively exploited?
As of the latest updates, there is no specific indication that CVE-2023-50456 is being actively exploited in the wild.