PT-2020-15048 · Otrs+2 · Otrs+3
Christoph Wuetschne
+1
·
Published
2020-03-27
·
Updated
2023-08-31
·
CVE-2020-1771
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS Community Edition versions 6.0.26 and prior
OTRS versions 7.0.15 and prior
Description
The issue allows an attacker to craft an article with a link to the customer address book containing malicious JavaScript content. When an agent opens this link, the JavaScript code is executed due to missing parameter encoding.
Recommendations
For OTRS Community Edition versions 6.0.26 and prior, update to a version later than 6.0.26.
For OTRS versions 7.0.15 and prior, update to a version later than 7.0.15.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Otrs
Otrs Community Edition
Suse