Zammad
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*
- <= 7.0.0
A cross-site request forgery (CSRF) vulnerability has been identified in Zammad, a web-based open-source helpdesk and customer support system. This issue affects versions of Zammad prior to 7.0.1 and 6.5.4. The vulnerability arises because the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not properly validate a CSRF state parameter. As a result, an attacker could potentially exploit this weakness to manipulate the OAuth authentication process.
Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, by exploiting the lack of CSRF protection in the OAuth callback process.
Users can upgrade to Zammad versions 7.0.1 or 6.5.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.