CyberRota Analysis
AI-GeneratedZammad versions 7.0.2 and 7.1.0 are vulnerable to a path traversal attack due to inadequate validation of session identifiers in their websocket and long-polling connection management. An authenticated attacker with low privileges can exploit this vulnerability to delete arbitrary files and directories on the server, posing a significant risk to data integrity. Organizations using the file-based session store should prioritize upgrading to versions 7.0.3 or 7.1.1 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated before being used to construct internal file paths. When the file-based session store is active (the default configuration), an authenticated attacker can manipulate the session identifier to reference locations outside the intended storage directory, leading to the deletion of arbitrary files and directories on the server. Exploitation requires only a low-privilege authenticated session and a single crafted request. Instances configured to use the Redis-based session store are not affected. This issue is fixed in versions 7.0.3 and 7.1.1.