SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2637

A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.

MEDIUM 6.1EPSS 4.30%

Does this matter?

Lower severity and a low EPSS score (4.30%). Track it; it rarely justifies an emergency change on its own.

Description

A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
4.30% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
otrs/faq · otrs/otrs itsm · opensuse/opensuse
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.