PT-2020-7405 · Otrs · Otrs Itsm+1

Published

2020-02-12

·

Updated

2024-06-15

·

CVE-2013-2637

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: OTRS ITSM versions prior to 3.2.4 OTRS ITSM versions prior to 3.1.8 OTRS ITSM versions prior to 3.0.7 FAQ versions prior to 2.1.4 FAQ versions prior to 2.0.8
Description: A Cross-Site Scripting (XSS) issue exists via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
Recommendations: For OTRS ITSM versions prior to 3.2.4, update to version 3.2.4 or later. For OTRS ITSM versions prior to 3.1.8, update to version 3.1.8 or later. For OTRS ITSM versions prior to 3.0.7, update to version 3.0.7 or later. For FAQ versions prior to 2.1.4, update to version 2.1.4 or later. For FAQ versions prior to 2.0.8, update to version 2.0.8 or later.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2637
OPENSUSE-SU-2024:10073-1

Affected Products

Faq
Otrs Itsm