CVE-2019-1010018: Zammad
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3.
Affected products
- Zammad Zammad: from 2.1.0, up to and including 2.1.2; from 2.2.0, up to and including 2.2.1; version 2.3.0 only
Published 2019-07-16. Last modified 2026-06-17.