Vulnerability Description
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zammad | Zammad | 5.0.2 |
References
- https://zammad.com/en/advisories/zaa-2021-21Vendor Advisory
- https://zammad.com/en/advisories/zaa-2021-21Vendor Advisory
FAQ
What is CVE-2021-44886?
CVE-2021-44886 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifi...
How severe is CVE-2021-44886?
CVE-2021-44886 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44886?
Check the references section above for vendor advisories and patch information. Affected products include: Zammad Zammad.