Apache Answer Basic Cross-Site Scripting Vulnerability

Vulnerability

A basic cross-site scripting vulnerability has been identified in Apache Answer versions through 2.0.0. This issue arises from improper neutralization of user-supplied content, which was included in notification emails without adequate escaping. As a result, authenticated users could inject arbitrary HTML into emails sent to other users.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected HTML could be executed in the context of the user's email client.

Remediation

Users are advised to upgrade to Apache Answer version 2.0.1, which addresses this vulnerability.

Added: Jun 9, 2026, 9:30 AM
Updated: Jun 9, 2026, 9:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
5.2
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.