VYPR
Medium severity6.5NVD Advisory· Published Jun 16, 2020· Updated Jun 17, 2026

CVE-2020-14214

CVE-2020-14214

Description

Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all tickets of an arbitrary Organization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Zammad/Zammad2 versions
    cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*range: <3.3.1
    • (no CPE)range: <3.3.1
  • Zammad/Zammaddescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.