VulnerabilityModified
CVE-2013-2637
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
MEDIUM 6.1EPSS 4.30%
Does this matter?
Lower severity and a low EPSS score (4.30%). Track it; it rarely justifies an emergency change on its own.
Description
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.30% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- otrs/faq · otrs/otrs itsm · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.htmlMailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/24922Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/58930Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83288Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.htmlMailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/24922Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/58930Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83288Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.