CyberRota Analysis
AI-GeneratedA vulnerability in Zammad's knowledge base management system allows users with restricted read permissions to access and interact with items beyond their assigned access scope due to insufficient data validation. This could lead to unauthorized data exposure, posing a significant risk to organizations using versions prior to 7.0.2. All users of Zammad should prioritize upgrading to version 7.0.2 or later to mitigate this high-severity issue.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked items was not fully enforced. This could have allowed users with limited read permissions to interact with items outside their assigned access scope. Data access has been strengthened in the current version through additional validation routines. This issue is fixed in version 7.0.2.