CVE-2017-5621: XSS
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5621?
CVE-2017-5621 is classified as a medium severity vulnerability due to the potential for exploitation through cross-site scripting (XSS).
How do I fix CVE-2017-5621?
To fix CVE-2017-5621, upgrade Zammad to version 1.0.4, 1.1.3, or 1.2.1 or later versions.
What versions of Zammad are affected by CVE-2017-5621?
Zammad versions before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1 are affected by CVE-2017-5621.
What type of exploit is associated with CVE-2017-5621?
CVE-2017-5621 is associated with a cross-site scripting (XSS) exploit that can occur through malicious HTML in chat messages or ticket articles.
What APIs are involved in the CVE-2017-5621 vulnerability?
CVE-2017-5621 can be triggered using either the REST API or the WebSocket API.