Apache Answer
- <= 2.0.0
A basic cross-site scripting vulnerability has been identified in Apache Answer versions through 2.0.0. This issue arises from improper neutralization of user-supplied content, which was included in notification emails without adequate escaping. As a result, authenticated users could inject arbitrary HTML into emails sent to other users.
Exploitation of this vulnerability allows for cross-site scripting, where injected HTML could be executed in the context of the user's email client.
Users are advised to upgrade to Apache Answer version 2.0.1, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.