Executive brief
Apache Answer, an open-source Q&A platform, is vulnerable to a security flaw where user-provided content is not properly cleaned before being included in notification emails. This allows an attacker with a standard user account to inject malicious code or formatting into emails sent to other users. Such an exploit could be used for phishing or to mislead users, potentially damaging the organization's reputation or leading to further account compromise.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Apache Answer versions up to and including 2.0.0. The root cause is the improper neutralization of script-related HTML tags (CWE-80) within the email notification component. An authenticated attacker can provide malicious input that is subsequently included in notification emails sent to other users without proper HTML escaping. When a recipient views the email in a client that renders HTML, the injected code may execute or alter the message's appearance. This vulnerability is fixed in version 2.0.1 by implementing proper escaping of dynamic content in email templates.
Affected products
- Apache Answer through 2.0.0
Timeline
- 2026-05-29: patched: Version 2.0.1 released
- 2026-06-09: disclosed: Public advisory published