In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
2025-04-05T21:15:39.450
2025-04-15T16:37:00.857
Analyzed
CVSSv3.1: 4.3 (MEDIUM)