CVE-2020-26029

MEDIUM WAF: Low
CVSS 6.5 Published: 2020-12-28
CWE-863

An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of header.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
zammadzammad1.0.0 - 3.4.1

References

Back to CVE Database