|
211301
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
|
CWE-352
Origin Validation Error
|
CVE-2020-26033
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211302
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can u…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26032
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211303
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26031
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211304
|
9.8 |
CRITICAL
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticate…
|
CWE-287
Improper Authentication
|
CVE-2020-26030
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211305
|
6.5 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not …
|
CWE-863
Incorrect Authorization
|
CVE-2020-26029
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211306
|
4.9 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
|
CWE-863
Incorrect Authorization
|
CVE-2020-26028
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211307
|
10.0 |
CRITICAL
Network
|
browserup
|
browserup_proxy
|
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it …
|
-
|
CVE-2020-26282
|
2024-11-21 14:19 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211308
|
8.5 |
HIGH
Network
|
gohugo
|
hugo
|
Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%…
|
CWE-78
OS Command
|
CVE-2020-26284
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211309
|
7.5 |
HIGH
Network
|
rust-lang
|
async-h1
|
async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async…
|
-
|
CVE-2020-26281
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211310
|
6.1 |
MEDIUM
Network
|
dbdeployer
|
dbdeployer
|
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files …
|
-
|
CVE-2020-26277
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|