CVE-2021-35300

MEDIUM

Zammad <4.0.0 - XSS

Title source: llm
STIX 2.1

Description

Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.

Scores

CVSS v3 4.3
EPSS 0.0040
EPSS Percentile 60.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-1021
Status published
Products (1)
zammad/zammad 1.0.0 - 4.0.0
Published Jun 28, 2021
Tracked Since Feb 18, 2026