Логотип exploitDog
bind:CVE-2020-10100
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10100

Количество 3

Количество 3

nvd логотип

CVE-2020-10100

почти 6 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, the application does not properly implement access controls related to this functionality. As such, users of one company are able to access ticket data from other companies. Due to the multi-tenant nature of this application, users who can access ticket details from one organization to the next allows for users to exfiltrate potentially sensitive data of other companies.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-10100

почти 6 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It allows for users ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w8qq-9h49-v34p

больше 3 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, the application does not properly implement access controls related to this functionality. As such, users of one company are able to access ticket data from other companies. Due to the multi-tenant nature of this application, users who can access ticket details from one organization to the next allows for users to exfiltrate potentially sensitive data of other companies.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-10100

An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, the application does not properly implement access controls related to this functionality. As such, users of one company are able to access ticket data from other companies. Due to the multi-tenant nature of this application, users who can access ticket details from one organization to the next allows for users to exfiltrate potentially sensitive data of other companies.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-10100

An issue was discovered in Zammad 3.0 through 3.2. It allows for users ...

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
github логотип
GHSA-w8qq-9h49-v34p

An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, the application does not properly implement access controls related to this functionality. As such, users of one company are able to access ticket data from other companies. Due to the multi-tenant nature of this application, users who can access ticket details from one organization to the next allows for users to exfiltrate potentially sensitive data of other companies.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу