Improper Neutralization of Script in Attributes in a Web Page in Zammad - #VU153216

 

Improper Neutralization of Script in Attributes in a Web Page in Zammad - #VU153216

Published: October 3, 2026


Vulnerability identifier: #VU153216
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-83
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to present misleading links or inject unwanted content into the page.

The vulnerability exists due to improper output escaping in AI error messages when displaying AI error messages containing link-style text. A remote user can influence AI error text containing link-style text to present misleading links or inject unwanted content into the page.

AI features must be enabled, and user interaction is required.


Affected software

Zammad

Remediation

Install security update from vendor's website.

Zammad - update to 7.1.3

External References

Related Security Bulletins