« Volver al listado

CVE-2017-5620

Estado: ModificadaMedia (6.1)—

An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5620",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-03-13T06:59:00.323",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/96937",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://zammad.com/de/news/security-advisory-zaa-2017-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/96937",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://zammad.com/de/news/security-advisory-zaa-2017-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema de XSS en Zammad en versiones anteriores a 1.0.4, 1.1.x en versiones anteriores a 1.1.3 y 1.2.x en versiones anteriores a 1.2.1. Los archivos adjuntos se abren en una nueva pestaña en lugar de descargarse. Esto crea un vector de ataque de código de ejecución en el dominio de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T01:20:51.807",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "113864CB-718D-4B62-BD84-587A1DE8ED19",
              "versionEndIncluding": "1.0.3"
            },
            {
              "criteria": "cpe:2.3:a:zammad:zammad:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7349B6BD-C108-4120-BD42-7FD3B39E46DA"
            },
            {
              "criteria": "cpe:2.3:a:zammad:zammad:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9F1D9BF-4A1B-4C55-89FE-AE174BD9994D"
            },
            {
              "criteria": "cpe:2.3:a:zammad:zammad:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "327D5DB8-7B7E-4BFA-8329-28BEB3BCE6C6"
            },
            {
              "criteria": "cpe:2.3:a:zammad:zammad:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A5511A6-864E-4069-951C-A0E0C38C6655"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}