Agent Account Privilege Escalation Vulnerability in Zammad Software by Zammad
CVE-2021-42086

8.8HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
7 October 2021

What is CVE-2021-42086?

A critical vulnerability in Zammad software prior to version 4.1.1 allows an Agent account to modify account data through crafted requests, enabling unauthorized administrative access. This flaw poses a significant security risk as it can lead to potential data manipulation and system compromise for users relying on this platform.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.