Home

Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

PUBLISHED Reserved 2026-03-25 | Published 2026-06-09 | Updated 2026-06-09 | Assigner apache

Problem types

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

Default status
unaffected

Any version
affected

Credits

Reimar Fritz reporter

References

www.openwall.com/lists/oss-security/2026/06/09/3

lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgj vendor-advisory

cve.org (CVE-2026-34033)

nvd.nist.gov (CVE-2026-34033)

Download JSON