
Cloud Vulnerability DB
A community-led vulnerabilities database
An SSRF (Server-Side Request Forgery) vulnerability was discovered in Zammad versions prior to 3.4.1. The vulnerability, tracked as CVE-2020-26032, was found in the SMS configuration interface for Massenversand functionality. The issue affects Zammad versions 1.0.x through 3.4.0 and was fixed in versions 3.4.1 and 3.5.0 (Zammad Advisory).
The vulnerability exists in the SMS configuration interface where the application renders the result of test requests to the user. This implementation allows an attacker to make GET requests to arbitrary URLs from the server's network interface. The vulnerability was rated as medium severity (Zammad Advisory).
The SSRF vulnerability could allow attackers to send unauthorized requests from the system to internal resources. This could potentially lead to the disclosure of sensitive information from internal systems that should not be accessible from external networks (Zammad Advisory).
An attacker can exploit this vulnerability by manipulating the SMS configuration interface to make requests to arbitrary URLs, which are then processed and rendered by the server (Zammad Advisory).
The vulnerability was fixed in Zammad versions 3.4.1 and 3.5.0. Users are recommended to upgrade to one of these fixed versions. Updates can be obtained through the official Zammad website, FTP server, or through the OS package manager (Zammad Advisory).
The vulnerability was discovered and reported by security researcher Michał Błaszczak, who works with Zdalny Admln (Zammad Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."