NA

CVE-2024-33668

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

An issue exists in Zammad prior to 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.