CVE-2020-26035: XSS
Published Dec 28, 2020
·Updated
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<3.4.1
Event History
Dec 28, 2020
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-26035?
The severity of CVE-2020-26035 is medium, with a severity value of 5.4.
2
How does CVE-2020-26035 affect Zammad?
CVE-2020-26035 affects Zammad versions before 3.4.1.
3
What type of vulnerability is CVE-2020-26035?
CVE-2020-26035 is a stored XSS vulnerability.
4
How can the vulnerability in CVE-2020-26035 be exploited?
The vulnerability in CVE-2020-26035 can be exploited by injecting malicious code into the Tags element in a Ticket in Zammad.
5
How can I fix CVE-2020-26035?
To fix CVE-2020-26035, upgrade Zammad to version 3.4.1 or later.