Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zammad zammad 6.2.0 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-50453
An issue exists in Zammad prior to 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
Zammad Zammad 6.1.0
Zammad Zammad 6.2.0
NA
CVE-2023-50454
An issue exists in Zammad prior to 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.
Zammad Zammad 6.1.0
Zammad Zammad 6.2.0
NA
CVE-2023-50455
An issue exists in Zammad prior to 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).
Zammad Zammad 6.1.0
Zammad Zammad 6.2.0
NA
CVE-2023-50457
An issue exists in Zammad prior to 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.
Zammad Zammad 6.1.0
Zammad Zammad 6.2.0
NA
CVE-2023-50456
An issue exists in Zammad prior to 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.
Zammad Zammad 6.1.0
Zammad Zammad 6.2.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started