Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rv2-fpjm-34hr

Опубликовано: 26 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

EPSS

Процентиль: 44%
0.00214
Низкий

8.6 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.6
nvd
почти 2 года назад

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

CVSS3: 8.6
debian
почти 2 года назад

An issue was discovered in Zammad before 6.3.0. Users with customer ac ...

EPSS

Процентиль: 44%
0.00214
Низкий

8.6 High

CVSS3

Дефекты

CWE-284