CVE-2020-10100
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with specific customers. However, the application does not properly implement access controls related to this functionality. As such, users of one company are able to access ticket data from other companies. Due to the multi-tenant nature of this application, users who can access ticket details from one organization to the next allows for users to exfiltrate potentially sensitive data of other companies.
Se detectó un problema en Zammad versiones 3.0 hasta 3.2. Permite a los usuarios visualizar los detalles de cliente del ticket asociados con clientes específicos. Sin embargo, la aplicación no implementa apropiadamente los controles de acceso relacionados con esta funcionalidad. Como tal, los usuarios de una compañía son capaces de acceder a los datos de tickets de otras compañías. Debido a la naturaleza multi-inquilino de esta aplicación, los usuarios que pueden acceder a los detalles de los tickets de una organización a otra permiten a los usuarios extraer datos potencialmente confidenciales de otras compañías.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-05 CVE Reserved
- 2020-03-05 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://zammad.com/news/security-advisory-zaa-2020-05 | 2021-07-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zammad Search vendor "Zammad" | Zammad Search vendor "Zammad" for product "Zammad" | >= 1.0.0 <= 3.2.0 Search vendor "Zammad" for product "Zammad" and version " >= 1.0.0 <= 3.2.0" | - |
Affected
|