ZeroHour

CVE-2021-35303

CVSS 3.1
6.1 medium
EPSS
<1%p55
Published
()
Modified
Description

Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.

Vendors
zammad
Products
zammad
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.