Lucene search

K
cvelistMitreCVELIST:CVE-2022-48023
HistoryFeb 03, 2023 - 12:00 a.m.

CVE-2022-48023

2023-02-0300:00:00
mitre
www.cve.org
insufficient privilege verification
zammad v5.3.0
authenticated attacker
ticket tags
zammad api
fixed
v5.3.1.

4.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.0%

Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.

4.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.0%

Related for CVELIST:CVE-2022-48023