Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote malicious users to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zammad zammad |