CVE-2024-33668

CRITICAL

Zammad < 6.3.0 - IDOR

Title source: rule
STIX 2.1

Description

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0033
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (2)
zammad/zammad 6.3.0 alpha
zammad/zammad 6.2.0 - 6.3.0
Published Apr 26, 2024
Tracked Since Feb 18, 2026