Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-42090 An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled. Zammad 4.1.1+ Fix from $2,3002021-10-07 CRITICAL 9.1 CVE-2021-42091 An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. Zammad 4.1.1+ Fix from $2,3002021-10-07 HIGH 8.8 CVE-2021-42086 An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request. Zammad 4.1.1+ Fix from $1,9502021-10-07 HIGH 7.5 CVE-2021-42089 An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information. Zammad 4.1.1+ Fix from $1,9502021-10-07 MEDIUM 6.5 CVE-2021-42084 An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless … Zammad 4.1.1+ Fix from $1,6002021-10-07 MEDIUM 6.1 CVE-2021-42088 An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled. Zammad 4.1.1+ Fix from $1,6002021-10-07 MEDIUM 5.4 CVE-2021-42085 An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar. Zammad 4.1.1+ Fix from $1,6002021-10-07 CRITICAL 9.8 CVE-2021-42094 An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages. Zammad 4.1.1+ Fix from $2,3002021-10-07 HIGH 7.2 CVE-2021-42093 An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers. Zammad 4.1.1+ Fix from $1,9502021-10-07 MEDIUM 5.4 CVE-2021-42092 An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket. Zammad 4.1.1+ Fix from $1,6002021-10-07 MEDIUM 6.1 CVE-2021-35303 Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute. Zammad after 4.0.0 Fix from $1,6002021-06-28 MEDIUM 5.3 CVE-2021-35301 Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view. Zammad after 4.0.0 Fix from $1,6002021-06-28 MEDIUM 5.3 CVE-2021-35302 Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information. Zammad after 4.0.0 Fix from $1,6002021-06-28 HIGH 7.5 CVE-2021-35299 Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing. Zammad after 4.0.0 Fix from $1,9502021-06-28 MEDIUM 6.1 CVE-2021-35298 Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that conta… Zammad after 4.0.0 Fix from $1,6002021-06-28 CRITICAL 9.8 CVE-2020-26030 An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure… Zammad 3.4.1+ Fix from $2,3002020-12-28 HIGH 7.5 CVE-2020-26032 An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the resul… Zammad 3.4.1+ Fix from $1,9502020-12-28 HIGH 7.5 CVE-2020-29160 An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing. Zammad 3.5.1+ Fix from $1,9502020-12-28 MEDIUM 6.5 CVE-2020-26029 An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization… Zammad 3.4.1+ Fix from $1,6002020-12-28 MEDIUM 5.4 CVE-2020-26033 An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check. Zammad 3.4.1+ Fix from $1,6002020-12-28 MEDIUM 5.4 CVE-2020-26035 An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket. Zammad 3.4.1+ Fix from $1,6002020-12-28 MEDIUM 6.5 CVE-2020-14214 Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can registe… Zammad 3.3.1+ Fix from $1,6002020-06-16 MEDIUM 5.4 CVE-2020-14213 In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge). Zammad 3.3.1+ Fix from $1,6002020-06-16 MEDIUM 5.4 CVE-2020-10103 An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality … Zammad after 3.2.0 Fix from $1,6002020-03-05 MEDIUM 5.3 CVE-2020-10105 An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET r… Zammad after 3.2.0 Fix from $1,6002020-03-05 HIGH 7.5 CVE-2020-10096 An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either rem… Zammad after 3.2.0 Fix from $1,9502020-03-05 HIGH 7.5 CVE-2020-10101 An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message… Zammad after 3.2.0 Fix from $1,9502020-03-05 MEDIUM 6.5 CVE-2020-10100 An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, t… Zammad after 3.2.0 Fix from $1,6002020-03-05 MEDIUM 5.4 CVE-2020-10098 An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The m… Zammad after 3.2.0 Fix from $1,6002020-03-05 MEDIUM 5.4 CVE-2020-10099 An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Za… Zammad after 3.2.0 Fix from $1,6002020-03-05