PT-2020-15043 · Otrs+2 · Otrs Community Edition+2
Anton Astaf’Ev
+1
·
Published
2020-01-10
·
Updated
2023-08-31
·
CVE-2020-1766
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS Community Edition versions 5.0.39 and prior versions
OTRS Community Edition versions 6.0.24 and prior versions
OTRS Community Edition versions 7.0.13 and prior versions
Description
The issue arises from improper handling of uploaded images, allowing malicious javascript to be executed in rare conditions. This occurs when a specially crafted SVG file is rendered as an inline jpg file, potentially forcing the agent's browser to execute the malicious code.
Recommendations
For OTRS Community Edition versions 5.0.39 and prior versions, update to a version later than 5.0.39 to resolve the issue.
For OTRS Community Edition versions 6.0.24 and prior versions, update to a version later than 6.0.24 to resolve the issue.
For OTRS Community Edition versions 7.0.13 and prior versions, update to a version later than 7.0.13 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Otrs Community Edition
Suse