CVE-2020-10099: XSS
Published Mar 5, 2020
·Updated
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens the ticket or has the ticket within the Toolbar.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=3.2.0
Remediation
Patch Available
Event History
Mar 5, 2020
CVE Published
via MITRE·12:38 AM
Data Sourced
via MITRE·12:38 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10099?
CVE-2020-10099 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-10099?
To fix CVE-2020-10099, upgrade Zammad to version 3.3 or higher where the vulnerability is addressed.
3
Who is affected by CVE-2020-10099?
All users of Zammad versions 3.0 through 3.2 are affected by CVE-2020-10099.
4
What type of vulnerability is CVE-2020-10099?
CVE-2020-10099 is an XSS (Cross-Site Scripting) vulnerability.
5
Can a low-privileged user exploit CVE-2020-10099?
Yes, a low-privileged user can exploit CVE-2020-10099 through the Ticket functionality.