Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-66765
HistorySep 29, 2022 - 12:00 a.m.

Zammad Access Control Error Vulnerability (CNVD-2022-66765)

2022-09-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
zammad
access control
vulnerability
version 5.2.1
germany
api
personal data

0.001 Low

EPSS

Percentile

29.2%

Zammad is a suite of ticket management software from Zammad Germany. version 5.2.1 of Zammad contains an access control error vulnerability, which stems from the existence of faulty access control in the program. Zammad’s asset handling mechanism has logic to ensure that client users cannot see other users’ personal information, and this logic is invalid when used over a Web socket connection. An authenticated attacker could use this vulnerability to query the Zammad API to obtain other users’ personal data.

CPENameOperatorVersion
zammad zammadeq5.2.1

0.001 Low

EPSS

Percentile

29.2%

Related for CNVD-2022-66765