CVE-2019-1010018: XSS
Published Jul 16, 2019
·Updated
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3.
Affected Software
3 affected components
Zammad Zammad>=2.1.0<=2.1.2
Zammad Zammad>=2.2.0<=2.2.1
Zammad Zammad=2.3.0
Remediation
Patch Available
Patch Available
Event History
Jul 16, 2019
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-1010018?
CVE-2019-1010018 is classified as a Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2019-1010018?
To fix CVE-2019-1010018, upgrade to Zammad version 2.3.1, 2.2.2, or 2.1.3.
3
What impact does CVE-2019-1010018 have?
CVE-2019-1010018 allows an attacker to execute JavaScript code in the browser of a user who opens a ticket.
4
Which versions are affected by CVE-2019-1010018?
CVE-2019-1010018 affects Zammad versions 2.3.0 and earlier.
5
What component is affected by CVE-2019-1010018?
The web application component is affected by CVE-2019-1010018.