Cross-Site Scripting Vulnerability in Apache Answer
CVE-2026-34033
5.4MEDIUM
What is CVE-2026-34033?
An improper neutralization of script-related HTML tags in Apache Answer allows authenticated users to inject arbitrary HTML into notification emails sent to other users. This vulnerability arises because user-supplied content is included in the emails without proper escaping. To remediate this issue, users should upgrade to version 2.0.1 to ensure that all user inputs are adequately sanitized, preventing potential exploitation.
Affected Version(s)
Apache Answer 0 <= 2.0.0