CVE-2021-35300: Medium severity zammad vulnerability
Published Jun 28, 2021
·Updated
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=4.0.0
Remediation
Patch Available
Event History
Jun 28, 2021
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-35300.
2
What is the severity of CVE-2021-35300?
CVE-2021-35300 has a severity rating of medium.
3
Which version of Zammad is affected by CVE-2021-35300?
CVE-2021-35300 affects Zammad versions 1.0.x up to 4.0.0.
4
What is the impact of CVE-2021-35300?
CVE-2021-35300 allows remote attackers to manipulate users into visiting the attackers' page.
5
Is there a fix available for CVE-2021-35300?
Yes, a fix for CVE-2021-35300 is available. Please refer to the advisory for more information.