CVE-2024-33666: Zammad
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
Affected products
- Zammad Zammad: from 6.2.0, before 6.3.0 (fixed in 6.3.0); version 6.3.0 only
Published 2024-04-26. Last modified 2026-06-17.