Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
References
Link | Resource |
---|---|
https://zammad.com/en/advisories/zaa-2023-01 | Vendor Advisory |
https://zammad.com/en/advisories/zaa-2023-01 | Vendor Advisory |
Configurations
History
30 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-346 |
Information
Published : 2023-05-02 16:15
Updated : 2025-01-30 17:15
NVD link : CVE-2023-29868
Mitre link : CVE-2023-29868
CVE.ORG link : CVE-2023-29868
JSON object : View
Products Affected
zammad
- zammad
CWE