CVE-2022-48023

Source
https://cve.org/CVERecord?id=CVE-2022-48023
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48023.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-48023
Published
2023-02-03T00:00:00Z
Modified
2026-07-15T01:48:54.334289439Z
Summary
[none]
Details

Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change ticket tags.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48023.json"
}
References

Affected packages

Git / github.com/zammad/zammad

Affected ranges

Type
GIT
Repo
https://github.com/zammad/zammad
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:zammad:zammad:5.3.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.3.0"
        },
        {
            "last_affected": "5.3.0"
        }
    ]
}

Affected versions

5.*
5.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48023.json"