Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-1000154

Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script code on users browser. This attack appear to be exploitable via the victim openning a ticket. This vulnerability appears to have been fixed in 2.3.1, 2.2.2 and 2.1.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-1000154
  • Zammad » Zammad » Version: 1.0.0
    cpe:2.3:a:zammad:zammad:1.0.0
  • Zammad » Zammad » Version: 1.0.1
    cpe:2.3:a:zammad:zammad:1.0.1
  • Zammad » Zammad » Version: 1.0.2
    cpe:2.3:a:zammad:zammad:1.0.2
  • Zammad » Zammad » Version: 1.0.3
    cpe:2.3:a:zammad:zammad:1.0.3
  • Zammad » Zammad » Version: 1.0.4
    cpe:2.3:a:zammad:zammad:1.0.4
  • Zammad » Zammad » Version: 1.1.0
    cpe:2.3:a:zammad:zammad:1.1.0
  • Zammad » Zammad » Version: 1.1.1
    cpe:2.3:a:zammad:zammad:1.1.1
  • Zammad » Zammad » Version: 1.1.2
    cpe:2.3:a:zammad:zammad:1.1.2
  • Zammad » Zammad » Version: 1.1.3
    cpe:2.3:a:zammad:zammad:1.1.3
  • Zammad » Zammad » Version: 1.1.4
    cpe:2.3:a:zammad:zammad:1.1.4
  • Zammad » Zammad » Version: 1.2.0
    cpe:2.3:a:zammad:zammad:1.2.0
  • Zammad » Zammad » Version: 1.2.1
    cpe:2.3:a:zammad:zammad:1.2.1
  • Zammad » Zammad » Version: 1.2.2
    cpe:2.3:a:zammad:zammad:1.2.2
  • Zammad » Zammad » Version: 1.2.3
    cpe:2.3:a:zammad:zammad:1.2.3
  • Zammad » Zammad » Version: 1.3.0
    cpe:2.3:a:zammad:zammad:1.3.0
  • Zammad » Zammad » Version: 1.3.1
    cpe:2.3:a:zammad:zammad:1.3.1
  • Zammad » Zammad » Version: 1.3.2
    cpe:2.3:a:zammad:zammad:1.3.2
  • Zammad » Zammad » Version: 1.4.0
    cpe:2.3:a:zammad:zammad:1.4.0
  • Zammad » Zammad » Version: 1.4.1
    cpe:2.3:a:zammad:zammad:1.4.1
  • Zammad » Zammad » Version: 1.5.0
    cpe:2.3:a:zammad:zammad:1.5.0
  • Zammad » Zammad » Version: 1.5.1
    cpe:2.3:a:zammad:zammad:1.5.1
  • Zammad » Zammad » Version: 1.6.0
    cpe:2.3:a:zammad:zammad:1.6.0
  • Zammad » Zammad » Version: 1.6.1
    cpe:2.3:a:zammad:zammad:1.6.1
  • Zammad » Zammad » Version: 2.0.0
    cpe:2.3:a:zammad:zammad:2.0.0
  • Zammad » Zammad » Version: 2.0.1
    cpe:2.3:a:zammad:zammad:2.0.1
  • Zammad » Zammad » Version: 2.1.0
    cpe:2.3:a:zammad:zammad:2.1.0
  • Zammad » Zammad » Version: 2.1.1
    cpe:2.3:a:zammad:zammad:2.1.1
  • Zammad » Zammad » Version: 2.1.2
    cpe:2.3:a:zammad:zammad:2.1.2
  • Zammad » Zammad » Version: 2.2.0
    cpe:2.3:a:zammad:zammad:2.2.0
  • Zammad » Zammad » Version: 2.2.1
    cpe:2.3:a:zammad:zammad:2.2.1
  • Zammad » Zammad » Version: 2.2.2
    cpe:2.3:a:zammad:zammad:2.2.2
  • Zammad » Zammad » Version: 2.3.0
    cpe:2.3:a:zammad:zammad:2.3.0


Contact Us

Shodan ® - All rights reserved