Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-05-02T00:00:00

Updated: 2024-08-02T14:14:40.000Z

Reserved: 2023-04-07T00:00:00

Link: CVE-2023-29868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-05-02T16:15:08.977

Modified: 2023-05-10T18:45:38.753

Link: CVE-2023-29868

cve-icon Redhat

No data.