PT-2019-11414 · Otrs+2 · Otrs+2

CVE-2019-10067

·

Publicado

2019-05-21

·

Atualizado

2023-01-20

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Open Ticket Request System (OTRS) versions 7.x through 7.0.6 Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.35 Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.17
Description: An issue was discovered in Open Ticket Request System (OTRS) where an attacker who is logged into OTRS as an agent user with appropriate permissions may manipulate the URL to cause execution of JavaScript in the context of OTRS.
Recommendations: For versions 7.x through 7.0.6, update to a version outside of this range to mitigate the risk. For Community Edition versions 5.0.x through 5.0.35, update to a version outside of this range to mitigate the risk. For Community Edition versions 6.0.x through 6.0.17, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting URL manipulation capabilities for agent users until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3068
ALT-PU-2019-3183
CVE-2019-10067
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Produtos afetados

Alt Linux
Otrs
Suse