CVE-2021-42092: XSS
Published Oct 7, 2021
·Updated
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
Affected Software
1 affected component
Zammad Zammad<4.1.1
Event History
Oct 7, 2021
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Zammad?
The vulnerability ID for this issue in Zammad is CVE-2021-42092.
2
What is the severity of CVE-2021-42092?
The severity of CVE-2021-42092 is medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2021-42092?
The affected software for CVE-2021-42092 is Zammad versions up to exclusive 4.1.1.
4
How does CVE-2021-42092 occur?
CVE-2021-42092 occurs via a stored XSS vulnerability during the addition of an attachment to a Ticket in Zammad.
5
How can I fix CVE-2021-42092 in Zammad?
To fix CVE-2021-42092 in Zammad, you should update to version 4.1.1 or higher.