CVE Vulnerabilities

CVE-2022-48022

Published: Feb 03, 2023 | Modified: Mar 26, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to view information about tickets they are not authorized to see.

Affected Software

Name Vendor Start Version End Version
Zammad Zammad 5.3.0 (including) 5.3.0 (including)

References