Zammad 是一款基于 Web 的开源帮助中心/客户支持系统。在 7.0.2 和 7.1.0 版本之前,Zammad 的 HTML sanitizers(HtmlSanitizer::Strict)会阻止 标签中的外部 URL,以防止远程内容加载;然而,同时被列入允许列表(allowlisted)的 属性并未受到相同的检查。这一疏忽使得攻击者只需发送一封电子邮件,即可在 标签的 属性中嵌入任意外部 URL,从而有效绕过外部内容防护机制。当客服人员查看包含恶意 的工单时,浏览器将静默加载攻击者控制的 URL,导致客
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84458 | 9.1 CRITICAL | Zammad: Account takeover via unverified email matching during SSO auto-link |
| CVE-2026-61525 | 8.8 HIGH | Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Control |
| CVE-2026-56733 | 8.7 HIGH | Zammad: Incorrect Authorization and Improper Privilege Management |
| CVE-2026-56725 | 8.7 HIGH | Zammad: Denial of Service via OTRS Import Controller |
| CVE-2026-84462 | 8.6 HIGH | Zammad: AI Agent template sanitizer bypass leads to remote code execution |
| CVE-2026-56731 | 8.4 HIGH | Zammad: Cross-Site Scripting in Ticket Notifications |
| CVE-2026-56724 | 7.1 HIGH | Zammad: Incorrect implementation of permission checks in the knowledge base module |
| CVE-2026-84465 | 7.1 HIGH | Zammad: S/MIME signature verification allows forged sender impersonation |
| CVE-2026-84464 | 7.1 HIGH | Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organizati |
| CVE-2026-56727 | 7.1 HIGH | Zammad: PGP signature spoofing via unvalidated verification return |
| CVE-2026-56723 | 7.1 HIGH | Zammad: Missing authorization on ticket attachment download |
| CVE-2026-84461 | 6.9 MEDIUM | Zammad: Missing rate limiting allows password brute-forcing during two-factor login |
| CVE-2026-63207 | 6.9 MEDIUM | Zammad: Sensitive Information Exposure in Integration Administration API |
| CVE-2026-84463 | 6.3 MEDIUM | Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switch |
| CVE-2026-56728 | 5.3 MEDIUM | Zammad: Cross-User Taskbar Item Access Control Vulnerability |
| CVE-2026-63206 | 5.3 MEDIUM | Zammad: Remote image tracking bypass via shortened URL scheme |
| CVE-2026-56734 | 5.3 MEDIUM | Zammad: Avatar Image URL Server-Side Request Forwarding |
| CVE-2026-56732 | 5.3 MEDIUM | Zammad: Malicious input in Ticket Body Enables Session Termination |
| CVE-2026-84460 | 5.3 MEDIUM | Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration |
| CVE-2026-61855 | 5.3 MEDIUM | Zammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound Mail |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet