First published: Mon Dec 28 2020(Updated: )
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | >=1.0.0<3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-26035 is medium, with a severity value of 5.4.
CVE-2020-26035 affects Zammad versions before 3.4.1.
CVE-2020-26035 is a stored XSS vulnerability.
The vulnerability in CVE-2020-26035 can be exploited by injecting malicious code into the Tags element in a Ticket in Zammad.
To fix CVE-2020-26035, upgrade Zammad to version 3.4.1 or later.