CVE-2022-27332
Last modified
CVE-2022-27332 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zammad | Zammad | < 5.1.0 |
References
- https://zammad.com/en/advisories/zaa-2022-01Patch, Vendor Advisory
- https://zammad.com/en/advisories/zaa-2022-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-27332?
How severe is CVE-2022-27332?
How do I fix CVE-2022-27332?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-27311Gibbon v3.4.4 and below allows attackers to execute a Server…9.8
- CVE-2022-27313An arbitrary file deletion vulnerability in Gitea v1.16.3 al…7.5
- CVE-2022-2732Missing Authorization in GitHub repository openemr/openemr p…8.3
- CVE-2022-2733Cross-site Scripting (XSS) - Reflected in GitHub repository …6.1
- CVE-2022-27330A cross-site scripting (XSS) vulnerability in /public/admin/…5.4
- CVE-2022-27331An access control issue in Zammad v5.0.3 broadcasts administ…4.3
- CVE-2022-27333idcCMS v1.10 was discovered to contain an issue which allows…7.5
- CVE-2022-27336Seacms v11.6 was discovered to contain a remote code executi…9.8
- CVE-2022-27337A logic error in the Hints::Hints function of Poppler v22.03…6.5
- CVE-2022-2734Improper Restriction of Rendered UI Layers or Frames in GitH…5.4
- CVE-2022-27340MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via…8.8
- CVE-2022-27341JFinalCMS v2.0 was discovered to contain a SQL injection vul…9.8
Are you affected by CVE-2022-27332?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
