Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x53p-mh39-7rgf

Опубликовано: 02 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

EPSS

Процентиль: 39%
0.00176
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

CVSS3: 6.5
debian
почти 3 года назад

Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Contro ...

EPSS

Процентиль: 39%
0.00176
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-346