PT-2026-47717 · Apache · Apache Answer
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Answer versions prior to 2.0.1
Description
An issue exists where user-supplied content is included in notification emails without proper escaping. This allows authenticated users to perform Cross-Site Scripting (XSS), which is the injection of malicious scripts into benign websites, by injecting arbitrary HTML into emails sent to other users.
Recommendations
Upgrade to version 2.0.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Answer