PT-2019-12716 · Otrs+2 · Otrs+3

Matthias Terlinde

·

Published

2019-06-11

·

Updated

2023-08-31

·

CVE-2019-12248

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 7.0.x through 7.0.7 Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19 Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36
Description An issue was discovered in Open Ticket Request System (OTRS) where an attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.
Recommendations For Open Ticket Request System (OTRS) versions 7.0.x through 7.0.7, update to a version outside of this range to mitigate the risk. For Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19, update to a version outside of this range to mitigate the risk. For Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the ability of agent users to quote emails from untrusted sources until a patch is available.

Fix

Related Identifiers

ALT-PU-2019-3068
ALT-PU-2019-3183
CVE-2019-12248
DLA-1816-1
DLA-1877-1
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Affected Products

Alt Linux
Otrs
Otrs Community Edition
Suse