Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-81952
HistoryOct 09, 2021 - 12:00 a.m.

Zammad Cross-Site Scripting Vulnerability (CNVD-2021-81952)

2021-10-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
zammad
cross-site scripting
chat
vulnerability
clipboard data
attack
code execution
cnvd-2021-81952

EPSS

0.001

Percentile

33.9%

Zammad is an open source web-based help desk/customer support system. a cross-site scripting vulnerability exists in the chat feature in versions of Zammad prior to 4.1.1. The vulnerability stems from improper handling of clipboard data. An attacker could exploit the vulnerability to execute malicious code.

EPSS

0.001

Percentile

33.9%

Related for CNVD-2021-81952