In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14213
Reference (s):
- https://github.com/zammad/zammad/commit/6e56aee25439b7a3211a6704a9d60453ad623ae4
- https://zammad.com/news/security-advisory-zaa-2020-13

