An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://zammad.com/news/security-advisory-zaa-2020-16 | vendor advisory |