CVE-2018-1000154: XSS
Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script code on users browser. This attack appear to be exploitable via the victim openning a ticket. This vulnerability appears to have been fixed in 2.3.1, 2.2.2 and 2.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000154?
CVE-2018-1000154 is classified as a medium severity vulnerability.
How do I fix CVE-2018-1000154?
To fix CVE-2018-1000154, upgrade to Zammad version 2.4.0 or later.
Where is CVE-2018-1000154 found?
CVE-2018-1000154 is found in Zammad versions up to and including 2.3.0.
What does CVE-2018-1000154 affect?
CVE-2018-1000154 affects the processing of email subjects in the Zammad web application.
What type of vulnerability is CVE-2018-1000154?
CVE-2018-1000154 is an improper neutralization of script-related HTML tags vulnerability.