Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-29868
HistoryMay 02, 2023 - 4:15 p.m.

Improper access control

2023-05-0216:15:00
PRIOn knowledge base
www.prio-n.com
5
improper access control
zammad 5.3.x
incorrect access control
unauthorized changes
articles
customer permissions

6.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.5%

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

CPENameOperatorVersion
zammadge5.3.0
zammadlt5.4.0

6.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.5%

Related for PRION:CVE-2023-29868