Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-36078

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.1%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2024-36078
  • Zammad » Zammad » Version: 6.3.0
    cpe:2.3:a:zammad:zammad:6.3.0


Contact Us

Shodan ® - All rights reserved