CVE-2022-27331 Information
Jun 07, 2022
cve
Description
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance including settings that should only be visible to authenticated users.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://zammad.com/de/advisories/zaa-2022-02
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: