PT-2026-98946 · Zammad · Zammad
CVE-2026-56732
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.0.2
Description
Zammad is a web-based open source helpdesk and customer support system. A flaw in the HTML sanitization process allows the injection of specific HTML elements into ticket bodies. When a user views a ticket containing these crafted elements, it can trigger an unauthorized logout request, which terminates the viewer's active session.
Recommendations
Update to version 7.0.2.
Exploit
Fix
CSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad