Cross-Site Scripting Vulnerability in Apache Answer
CVE-2026-34033

5.4MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 June 2026

What is CVE-2026-34033?

An improper neutralization of script-related HTML tags in Apache Answer allows authenticated users to inject arbitrary HTML into notification emails sent to other users. This vulnerability arises because user-supplied content is included in the emails without proper escaping. To remediate this issue, users should upgrade to version 2.0.1 to ensure that all user inputs are adequately sanitized, preventing potential exploitation.

Affected Version(s)

Apache Answer 0 <= 2.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reimar Fritz
.