Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zammad MEDIUM 5.3
CVE-2020-10097

An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure in…

Fix: after 3.2.0
Fix from $1,600 2020-03-05
Zammad MEDIUM 5.3
CVE-2020-10102

An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to g…

Fix: after 3.2.0
Fix from $1,600 2020-03-05
Zammad MEDIUM 6.1
CVE-2019-1010018

Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. T…

Fix: after 2.2.1
Fix from $1,600 2019-07-16
Zammad MEDIUM 6.1
CVE-2018-1000154

Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in t…

Fix: after 2.3.0
Fix from $1,600 2018-04-05
Zammad CRITICAL 9.8
CVE-2017-5619

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g.…

Fix: after 1.0.3
Fix from $2,300 2017-03-13
Zammad CRITICAL 9.8
CVE-2017-6080

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP A…

Fix: after 1.0.3
Fix from $2,300 2017-03-13
Zammad HIGH 8.8
CVE-2017-6081

A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cr…

Fix: after 1.0.3
Fix from $1,950 2017-03-13
Zammad MEDIUM 6.1
CVE-2017-5620

An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of gettin…

Fix: after 1.0.3
Fix from $1,600 2017-03-13
Zammad MEDIUM 6.1
CVE-2017-5621

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message…

Fix: after 1.0.3
Fix from $1,600 2017-03-13