CVE-2024-33666: High severity zammad vulnerability
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33666?
CVE-2024-33666 is classified as a high severity vulnerability due to unauthorized access to sensitive time accounting details.
How do I fix CVE-2024-33666?
To fix CVE-2024-33666, upgrade Zammad to version 6.3.0 or later to ensure customers cannot access agent-only data via the API.
Who is affected by CVE-2024-33666?
Users with customer access to tickets in Zammad prior to version 6.3.0 are affected by CVE-2024-33666.
What data can be accessed due to CVE-2024-33666?
CVE-2024-33666 allows unauthorized users to access time accounting details related to tickets via the API.
Is CVE-2024-33666 a local or remote vulnerability?
CVE-2024-33666 is categorized as a remote vulnerability since it can be exploited via the API by any user with customer access.