CVE-2020-29160
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
Date published : 2020-12-28
https://github.com/zammad/zammad/commit/28944de180a88698509a656f61558bf9d7f810f4