PT-2020-15048 · Otrs+2 · Otrs+3

Christoph Wuetschne

+1

·

Published

2020-03-27

·

Updated

2023-08-31

·

CVE-2020-1771

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OTRS Community Edition versions 6.0.26 and prior OTRS versions 7.0.15 and prior
Description The issue allows an attacker to craft an article with a link to the customer address book containing malicious JavaScript content. When an agent opens this link, the JavaScript code is executed due to missing parameter encoding.
Recommendations For OTRS Community Edition versions 6.0.26 and prior, update to a version later than 6.0.26. For OTRS versions 7.0.15 and prior, update to a version later than 7.0.15.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2649
ALT-PU-2020-2748
CVE-2020-1771
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Affected Products

Alt Linux
Otrs
Otrs Community Edition
Suse