Information Disclosure Vulnerability in Zammad by Zammad GmbH
CVE-2023-50457

4.3MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
10 December 2023

What is CVE-2023-50457?

A vulnerability exists in Zammad versions prior to 6.2.0, where a flawed permission check allows users to access knowledge base entries linked to tickets they do not have permission to view. This exposure could lead to the unauthorized disclosure of sensitive information, potentially affecting user privacy and data integrity within the system.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.