Impact
Zammad’s ticket article attachment cloning endpoint allows an authenticated user to clone attachments from tickets without proper authorization checks. The flaw can be exploited to view or copy sensitive documents that the attacker’s role should not access. This results in confidentiality violations, as data from unrelated tickets may be disclosed to unauthorized users, and potentially impacts the integrity of the ticket system if attachments are duplicated incorrectly.
Affected Systems
The vulnerability affects the Zammad help desk software, specifically versions around 7.1.0. Users running Zammad 7.1.0 (and the earlier 7.0.1 release referenced in the advisory) are at risk. The issue exists on all operating systems supported by Zammad, as indicated by the CPE entries for Linux, macOS, and Windows.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. Although no EPSS score is available, the lack of an exploit in CISA’s KEV list suggests the risk is moderate relative to other high‑severity flaws. Because the attack requires authentication, an attacker must first gain valid credentials—typically via legitimate user access or compromised accounts. Once authenticated, they can target any ticket attachment, potentially exposing private data or escalating privileges within the ticketing system.
OpenCVE Enrichment