CVE-2026-63216
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 02:46
Descrizione
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, the option label is output as raw HTML without escaping. An attacker who can control an option label, for example by setting a malicious string as a user or organization name used in a relation attribute, or by supplying a crafted custom attribute option value, can inject arbitrary HTML and JavaScript. The payload executes in the browser of any admin or agent who opens the affected object attribute configuration view. This issue is fixed in version 7.1.2.
Alias e classificazioni
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
Riferimenti pubblici
- https://github.com/zammad/zammad/commit/74b4fd4db62dc3652bb9db24096a2fbd1b56dc7f
https://github.com/zammad/zammad/commit/74b4fd4db62dc3652bb9db24096a2fbd1b56dc7f - https://github.com/zammad/zammad/security/advisories/GHSA-r95m-ghj7-646x
https://github.com/zammad/zammad/security/advisories/GHSA-r95m-ghj7-646x
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.