Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-81947
HistoryOct 13, 2021 - 12:00 a.m.

Zammad licensing issue vulnerability

2021-10-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

36.0%

Zammad is a suite of ticket management software from Zammad, a German company. Zammad is vulnerable to authorization issues in versions prior to 5.0.1, which stem from a lack of authentication measures or insufficient authentication strength in the network system or product. An attacker could use special request software to view a list of tickets displaying titles, states, etc. without the privileges that should have been required.

CPENameOperatorVersion
zammad zammadlt5.0.1

0.001 Low

EPSS

Percentile

36.0%

Related for CNVD-2021-81947