CVE-2017-5621: Zammad
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.
Affected products
- Zammad Zammad: up to and including 1.0.3; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.2.0 only
Published 2017-03-13. Last modified 2026-06-17.