VYPR
Medium severity6.1NVD Advisory· Published Jul 16, 2019· Updated Jun 17, 2026

CVE-2019-1010018

CVE-2019-1010018

Description

Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java script code on users browser. The component is: web app. The attack vector is: the victim must open a ticket. The fixed version is: 2.3.1, 2.2.2 and 2.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Zammad/Zammad4 versions
    cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*range: >=2.1.0,<=2.1.2
    • cpe:2.3:a:zammad:zammad:2.3.0:*:*:*:*:*:*:*
    • (no CPE)range: <=2.3.0
    • (no CPE)range: ≤ 2.3.0 [fixed: 2.3.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.