Stored data: URI XSS / Phishing via Zammad's HTML Sanitizer (CVE-2026-34718)
A one-scheme gap in Zammad’s link sanitizer let a data:text/html anchor survive into stored ticket articles — a stored phishing primitive delivered through inbound email.
A one-scheme gap in Zammad’s link sanitizer let a data:text/html anchor survive into stored ticket articles — a stored phishing primitive delivered through inbound email.