An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. Attackers are also able to gain unauthorized access to existing tickets.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35894 | An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. Attackers are also able to gain unauthorized access to existing tickets. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://zammad.com/de/advisories/zaa-2023-03 |
|
History
Wed, 22 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-22T14:38:04.811Z
Reserved: 2023-04-29T00:00:00.000Z
Link: CVE-2023-31597
Updated: 2024-08-02T14:53:30.911Z
Status : Modified
Published: 2023-05-18T18:15:10.017
Modified: 2025-01-22T15:15:08.770
Link: CVE-2023-31597
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD