Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2021-42090
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
Zammad
4.1.1+
CRITICAL 9.1
CVE-2021-42091
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
Zammad
4.1.1+
HIGH 8.8
CVE-2021-42086
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
Zammad
4.1.1+
HIGH 7.5
CVE-2021-42089
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
Zammad
4.1.1+
MEDIUM 6.5
CVE-2021-42084
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless …
Zammad
4.1.1+
MEDIUM 6.1
CVE-2021-42088
An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.
Zammad
4.1.1+
MEDIUM 5.4
CVE-2021-42085
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
Zammad
4.1.1+
CRITICAL 9.8
CVE-2021-42094
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
Zammad
4.1.1+
HIGH 7.2
CVE-2021-42093
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.
Zammad
4.1.1+
MEDIUM 5.4
CVE-2021-42092
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
Zammad
4.1.1+
MEDIUM 6.1
CVE-2021-35303
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.
Zammad
after 4.0.0
MEDIUM 5.3
CVE-2021-35301
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
Zammad
after 4.0.0
MEDIUM 5.3
CVE-2021-35302
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
Zammad
after 4.0.0
HIGH 7.5
CVE-2021-35299
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
Zammad
after 4.0.0
MEDIUM 6.1
CVE-2021-35298
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that conta…
Zammad
after 4.0.0
CRITICAL 9.8
CVE-2020-26030
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…
Zammad
3.4.1+
HIGH 7.5
CVE-2020-26032
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the resul…
Zammad
3.4.1+
HIGH 7.5
CVE-2020-29160
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
Zammad
3.5.1+
MEDIUM 6.5
CVE-2020-26029
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization…
Zammad
3.4.1+
MEDIUM 5.4
CVE-2020-26033
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
Zammad
3.4.1+
MEDIUM 5.4
CVE-2020-26035
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
Zammad
3.4.1+
MEDIUM 6.5
CVE-2020-14214
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can registe…
Zammad
3.3.1+
MEDIUM 5.4
CVE-2020-14213
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
Zammad
3.3.1+
MEDIUM 5.4
CVE-2020-10103
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality …
Zammad
after 3.2.0
MEDIUM 5.3
CVE-2020-10105
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET r…
Zammad
after 3.2.0
HIGH 7.5
CVE-2020-10096
An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either rem…
Zammad
after 3.2.0
HIGH 7.5
CVE-2020-10101
An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message…
Zammad
after 3.2.0
MEDIUM 6.5
CVE-2020-10100
An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, t…
Zammad
after 3.2.0
MEDIUM 5.4
CVE-2020-10098
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The m…
Zammad
after 3.2.0
MEDIUM 5.4
CVE-2020-10099
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Za…
Zammad
after 3.2.0