CVE-2020-10098
05.03.2020, 01:15
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browser of any user who opens the Ticket with the Article created from that Email.
Vendor | Product | Version |
---|---|---|
zammad | zammad | 1.0.0 ≤ 𝑥 ≤ 3.2.0 |
𝑥
= Vulnerable software versions