CVE-2020-26033

MEDIUM WAF: Low
CVSS 5.4 Published: 2020-12-28
CWE-352

An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.

WAF Coverage Analysis

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
zammadzammad1.0.0 - 3.4.1

References

Back to CVE Database