Описание
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6.2.0 (включая) до 6.3.0 (исключая)
Одно из
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:6.3.0:alpha:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00214
Низкий
8.6 High
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 8.6
debian
почти 2 года назад
An issue was discovered in Zammad before 6.3.0. Users with customer ac ...
CVSS3: 8.6
github
почти 2 года назад
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
EPSS
Процентиль: 44%
0.00214
Низкий
8.6 High
CVSS3
Дефекты
CWE-284