5.9
CVSSv3

CVE-2023-50454

Published: 10/12/2023 Updated: 13/12/2023
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An issue exists in Zammad prior to 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.

Vulnerable Product Search on Vulmon Subscribe to Product

zammad zammad 6.1.0

zammad zammad 6.2.0