An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
Published October 7, 2021.
Zammad Zammad