CVE-2017-5620: XSS
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5620?
CVE-2017-5620 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2017-5620?
To fix CVE-2017-5620, upgrade Zammad to version 1.0.4 or later for 1.0.x, version 1.1.3 or later for 1.1.x, or version 1.2.1 or later for 1.2.x.
What versions of Zammad are affected by CVE-2017-5620?
CVE-2017-5620 affects Zammad versions prior to 1.0.4, 1.1.0-1.1.2, and 1.2.0.
What impact does CVE-2017-5620 have?
CVE-2017-5620 can allow an attacker to execute malicious scripts in the context of the victim's browser.
Is there a workaround for CVE-2017-5620 if I can't upgrade Zammad?
No specific workaround exists for CVE-2017-5620; upgrading to a secure version is the recommended solution.