CVE-2023-29868 Information
May 04, 2023
cve
Description
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
Reference
https://zammad.com/en/advisories/zaa-2023-01
Share on: