An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-42090.json"