An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
References
Link | Resource |
---|---|
https://zammad.com/en/advisories/zaa-2022-01 | Patch Vendor Advisory |
Configurations
Information
Published : 2022-04-26 20:15
Updated : 2022-05-05 12:39
NVD link : CVE-2022-27332
Mitre link : CVE-2022-27332
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
zammad
- zammad