An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-42093.json"