Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
References
Link | Resource |
---|---|
https://zammad.com/en/advisories/zaa-2023-01 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-05-02 16:15
Updated : 2023-05-10 18:45
NVD link : CVE-2023-29868
Mitre link : CVE-2023-29868
CVE.ORG link : CVE-2023-29868
JSON object : View
Products Affected
zammad
- zammad
CWE