CVE-2020-10105: Zammad
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file 404.html (/zammad/public/404.html)
Affected products
- Zammad Zammad: from 1.0.0, up to and including 3.2.0
Published 2020-03-05. Last modified 2026-06-17.