CVE-2021-35298
https://notcve.org/view.php?id=CVE-2021-35298
28 Jun 2021 — Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information. Una vulnerabilidad de tipo Cross Site Scripting (XSS) en Zammad versiones 1.0.x hasta 4.0.0, permite a atacantes remotos ejecutar scripts web o HTML arbitrarios por medio de múltiples modelos que contienen un campo "note" para almacenar información adicional • https://zammad.com/en/advisories/zaa-2021-03 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-35299
https://notcve.org/view.php?id=CVE-2021-35299
28 Jun 2021 — Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing. Un Control de Acceso Incorrecto en Zammad versiones 1.0.x hasta 4.0.0, permite a atacantes obtener información confidencial por medio de sondeo de la configuración de la conexión de correo electrónico • https://zammad.com/en/advisories/zaa-2021-02 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2021-35300
https://notcve.org/view.php?id=CVE-2021-35300
28 Jun 2021 — Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page. Una Inyección de texto / de Suplantación de Contenido en la página 404 en Zammad versiones 1.0.x hasta 4.0.0, podría permitir a atacantes remotos manipular a los usuarios para que visiten la página de los atacantes • https://zammad.com/en/advisories/zaa-2021-07 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
CVE-2021-35301
https://notcve.org/view.php?id=CVE-2021-35301
28 Jun 2021 — Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view. Un Control de Acceso Incorrecto en Zammad versiones 1.0.x hasta 4.0.0, permite a atacantes remotos obtener información confidencial por medio de la visualización de detalles Ticket Article • https://zammad.com/en/advisories/zaa-2021-05 •
CVE-2021-35302
https://notcve.org/view.php?id=CVE-2021-35302
28 Jun 2021 — Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information. Un Control de Acceso Incorrecto para los Tickets vinculados en Zammad versiones 1.0.x hasta 4.0.0, permite a atacantes remotos obtener información confidencial • https://zammad.com/en/advisories/zaa-2021-04 •
CVE-2021-35303
https://notcve.org/view.php?id=CVE-2021-35303
28 Jun 2021 — Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute. Una vulnerabilidad de tipo Cross Site Scripting (XSS) en Zammad versiones 1.0.x hasta 4.0.0, permite a atacantes remotos ejecutar un script web o HTML arbitrario por medio del atributo User Avatar • https://zammad.com/en/advisories/zaa-2021-06 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-26028
https://notcve.org/view.php?id=CVE-2020-26028
28 Dec 2020 — An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets. Se detectó un problema en Zammad versiones anteriores a 3.4.1. Los Usuarios Administradores sin un permiso ticket.* pueden acceder a Tickets • https://zammad.com/news/security-advisory-zaa-2020-19 • CWE-863: Incorrect Authorization •
CVE-2020-26029
https://notcve.org/view.php?id=CVE-2020-26029
28 Dec 2020 — An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of header. Se detectó un problema en Zammad versiones anteriores a 3.4.1. Se presentan unas comprobaciones de autorización incorrectas para peticiones de suplantación de identidad por medio de X-On-Behalf-Of. • https://zammad.com/news/security-advisory-zaa-2020-20 • CWE-863: Incorrect Authorization •
CVE-2020-26030
https://notcve.org/view.php?id=CVE-2020-26030
28 Dec 2020 — An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users. Se detectó un problema en Zammad versiones anteriores a 3.4.1. Se presenta una omisión de autenticación en el endpoint de SSO por medio de un encabezado diseñado, cuando la SSO no está configurada. • https://zammad.com/news/security-advisory-zaa-2020-18 • CWE-287: Improper Authentication •
CVE-2020-26031
https://notcve.org/view.php?id=CVE-2020-26031
28 Dec 2020 — An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions). Se detectó un problema en Zammad versiones anteriores a 3.4.1. La funcionalidad global-search filtra los borradores Knowledge Base a los lectores Knowledge Base (que están autenticados pero no presentan permisos suficientes) • https://zammad.com/news/security-advisory-zaa-2020-16 • CWE-276: Incorrect Default Permissions •