PT-2026-99088 · Zammad · Zammad
CVE-2026-84463
·
Published
2026-09-25
·
Updated
2026-09-29
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
Users with Knowledge Base editing rights for a category can embed a video widget in a published answer using a specially crafted value. Because this value is inserted into the page HTML without being escaped for its attribute context, it allows the injection of additional HTML. When a user with session-switching permissions views the affected answer, the injected HTML triggers a silent request to the session-switching endpoint using the viewer's active credentials. This action switches the viewer's session to an account selected by the author of the Knowledge Base answer.
Recommendations
Update to version 7.1.2.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad