CVE-2021-35298: XSS
Published Jun 28, 2021
·Updated
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=4.0.0
Event History
Jun 28, 2021
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Cross Site Scripting (XSS) vulnerability in Zammad?
The vulnerability ID is CVE-2021-35298.
2
What is the severity of CVE-2021-35298?
The severity of CVE-2021-35298 is medium with a severity value of 6.1.
3
Which versions of Zammad are affected by CVE-2021-35298?
Zammad versions 1.0.x up to 4.0.0 are affected by CVE-2021-35298.
4
How can remote attackers exploit CVE-2021-35298?
Remote attackers can exploit CVE-2021-35298 by executing arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
5
Where can I find more information about CVE-2021-35298?
You can find more information about CVE-2021-35298 in the advisory published by Zammad at the following link: https://zammad.com/en/advisories/zaa-2021-03.