Medium
CVSS 4.3
Overview
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissio...
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: