CVE-2018-1000154
Summary
| CVE | CVE-2018-1000154 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-05 13:29:00 UTC |
| Updated | 2018-05-10 14:43:00 UTC |
| Description | Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script code on users browser. This attack appear to be exploitable via the victim openning a ticket. This vulnerability appears to have been fixed in 2.3.1, 2.2.2 and 2.1.3. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XSS issue - placeholder · Issue #1869 · zammad/zammad · GitHub | CONFIRM | github.com | Third Party Advisory |
| Zammad – Helpdesk & Support Software | Release: Zammad 2.4.0 & 2.3.1 & 2.2.2 (major & patchlevel) | CONFIRM | zammad.com | Vendor Advisory |
| Zammad – Helpdesk & Support Software | Zammad Security Advisory ZAA-2018-01 | CONFIRM | zammad.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.