Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zammad CRITICAL 9.8
CVE-2021-42090

An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

Fix: 4.1.1+
Fix from $2,300 2021-10-07
Zammad CRITICAL 9.1
CVE-2021-42091

An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

Fix: 4.1.1+
Fix from $2,300 2021-10-07
Zammad HIGH 8.8
CVE-2021-42086

An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

Fix: 4.1.1+
Fix from $1,950 2021-10-07
Zammad HIGH 7.5
CVE-2021-42089

An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.

Fix: 4.1.1+
Fix from $1,950 2021-10-07
Zammad MEDIUM 6.5
CVE-2021-42084

An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless …

Fix: 4.1.1+
Fix from $1,600 2021-10-07
Zammad MEDIUM 6.1
CVE-2021-42088

An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.

Fix: 4.1.1+
Fix from $1,600 2021-10-07
Zammad MEDIUM 5.4
CVE-2021-42085

An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.

Fix: 4.1.1+
Fix from $1,600 2021-10-07
Zammad CRITICAL 9.8
CVE-2021-42094

An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

Fix: 4.1.1+
Fix from $2,300 2021-10-07
Zammad HIGH 7.2
CVE-2021-42093

An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.

Fix: 4.1.1+
Fix from $1,950 2021-10-07
Zammad MEDIUM 5.4
CVE-2021-42092

An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.

Fix: 4.1.1+
Fix from $1,600 2021-10-07
Zammad MEDIUM 6.1
CVE-2021-35303

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.

Fix: after 4.0.0
Fix from $1,600 2021-06-28
Zammad MEDIUM 5.3
CVE-2021-35301

Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.

Fix: after 4.0.0
Fix from $1,600 2021-06-28
Zammad MEDIUM 5.3
CVE-2021-35302

Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.

Fix: after 4.0.0
Fix from $1,600 2021-06-28
Zammad HIGH 7.5
CVE-2021-35299

Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.

Fix: after 4.0.0
Fix from $1,950 2021-06-28
Zammad MEDIUM 6.1
CVE-2021-35298

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that conta…

Fix: after 4.0.0
Fix from $1,600 2021-06-28
Zammad CRITICAL 9.8
CVE-2020-26030

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…

Fix: 3.4.1+
Fix from $2,300 2020-12-28
Zammad HIGH 7.5
CVE-2020-26032

An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the resul…

Fix: 3.4.1+
Fix from $1,950 2020-12-28
Zammad HIGH 7.5
CVE-2020-29160

An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.

Fix: 3.5.1+
Fix from $1,950 2020-12-28
Zammad MEDIUM 6.5
CVE-2020-26029

An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization…

Fix: 3.4.1+
Fix from $1,600 2020-12-28
Zammad MEDIUM 5.4
CVE-2020-26033

An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.

Fix: 3.4.1+
Fix from $1,600 2020-12-28
Zammad MEDIUM 5.4
CVE-2020-26035

An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.

Fix: 3.4.1+
Fix from $1,600 2020-12-28
Zammad MEDIUM 6.5
CVE-2020-14214

Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can registe…

Fix: 3.3.1+
Fix from $1,600 2020-06-16
Zammad MEDIUM 5.4
CVE-2020-14213

In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).

Fix: 3.3.1+
Fix from $1,600 2020-06-16
Zammad MEDIUM 5.4
CVE-2020-10103

An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality …

Fix: after 3.2.0
Fix from $1,600 2020-03-05
Zammad MEDIUM 5.3
CVE-2020-10105

An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET r…

Fix: after 3.2.0
Fix from $1,600 2020-03-05
Zammad HIGH 7.5
CVE-2020-10096

An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either rem…

Fix: after 3.2.0
Fix from $1,950 2020-03-05
Zammad HIGH 7.5
CVE-2020-10101

An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message…

Fix: after 3.2.0
Fix from $1,950 2020-03-05
Zammad MEDIUM 6.5
CVE-2020-10100

An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, t…

Fix: after 3.2.0
Fix from $1,600 2020-03-05
Zammad MEDIUM 5.4
CVE-2020-10098

An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The m…

Fix: after 3.2.0
Fix from $1,600 2020-03-05
Zammad MEDIUM 5.4
CVE-2020-10099

An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Za…

Fix: after 3.2.0
Fix from $1,600 2020-03-05