Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hh5m-6r25-ccqm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.

An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.

EPSS

Процентиль: 30%
0.00112
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 5 лет назад

An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.

CVSS3: 4.3
debian
около 5 лет назад

An issue was discovered in Zammad before 3.5.1. An Agent with Customer ...

EPSS

Процентиль: 30%
0.00112
Низкий

Дефекты

CWE-863