CyberRota Analysis
AI-GeneratedThe External Data Source feature in Zammad prior to version 7.1.2 is vulnerable, allowing authenticated users, even those with basic customer access, to access sensitive information about tickets, customer accounts, teams, or organizations that they should not be able to see. This could lead to unauthorized disclosure of confidential data, posing a significant risk to user privacy and data integrity. Organizations using affected versions of Zammad should prioritize upgrading to version 7.1.2 to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, user, group, or organization before including its details in a request to that external system. An authenticated user, including one with only basic customer access, could exploit this by referencing another record's ID, and thereby view details of tickets, customer accounts, teams, or organizations that did not belong to them. This issue is fixed in version 7.1.2.