CVE-2024-49193
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 12, 2024
Updated: Oct 16, 2024
CWE ID 290
Summary
CVE-2024-49193 is a vulnerability affecting Zendesk before July 2024. It enables remote attackers to access ticket history by spoofing email addresses. The issue arises due to the use of Cc fields from incoming emails to grant additional authorization for ticket viewing. However, the mechanism to detect spoofed emails is deficient. Furthermore, the support email addresses linked to individual tickets are predictable, increasing the risk of successful attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Zendesk