Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Anton Astafev

#43352of 53,632
6.1Total CVSS
Vulnerabilities · 1
PT-2020-15043
6.1
2020-01-10
Otrs · Otrs Community Edition · CVE-2020-1766
**Name of the Vulnerable Software and Affected Versions** OTRS Community Edition versions 5.0.39 and prior versions OTRS Community Edition versions 6.0.24 and prior versions OTRS Community Edition versions 7.0.13 and prior versions **Description** The issue arises from improper handling of uploaded images, allowing malicious javascript to be executed in rare conditions. This occurs when a specially crafted SVG file is rendered as an inline jpg file, potentially forcing the agent's browser to execute the malicious code. **Recommendations** For OTRS Community Edition versions 5.0.39 and prior versions, update to a version later than 5.0.39 to resolve the issue. For OTRS Community Edition versions 6.0.24 and prior versions, update to a version later than 6.0.24 to resolve the issue. For OTRS Community Edition versions 7.0.13 and prior versions, update to a version later than 7.0.13 to resolve the issue.