Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgj | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/06/09/3 | Mailing List |
Configurations
History
11 Jun 2026, 15:35
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache answer |
|
| CPE | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgj - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/09/3 - Mailing List | |
| CWE | CWE-79 |
09 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
09 Jun 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 09:16
Updated : 2026-06-11 15:35
NVD link : CVE-2026-34033
Mitre link : CVE-2026-34033
CVE.ORG link : CVE-2026-34033
JSON object : View
Products Affected
apache
- answer
