CyberRota Analysis
AI-GeneratedZammad 7.1.0 is vulnerable due to an improper authorization flaw in the ticket article attachment cloning endpoint, allowing authenticated users to potentially access or manipulate attachments they should not have permissions for. This could lead to unauthorized disclosure of sensitive information or data integrity issues. Organizations using this version of Zammad should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.