Zammad 6.3.0 至 6.5.4 版本存在一个会话劫持漏洞,该漏洞可导致以 zammad 用户身份执行远程代码。该漏洞同样存在于 7.0.0 至 7.1.3 版本中,但由于环境条件限制,无法被实际利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zammad GmbH | Zammad | *< 6.3.0 |
unknown |
6.3.0< 6.5.4 |
affected | ||
7.0.0< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zammad GmbH | Zammad | 6.3.0 ~ 6.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet