Improper Neutralization of Script in Attributes in a Web Page in Zammad - #VU153216
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to present misleading links or inject unwanted content into the page.
The vulnerability exists due to improper output escaping in AI error messages when displaying AI error messages containing link-style text. A remote user can influence AI error text containing link-style text to present misleading links or inject unwanted content into the page.
AI features must be enabled, and user interaction is required.