VulnerabilityModified
CVE-2014-1695
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML email.
MEDIUM 4.3EPSS 4.91%
Does this matter?
Lower severity and a low EPSS score (4.91%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML email.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.91% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- otrs/otrs
- Source
- cve@mitre.org
References
- http://adamziaja.com/poc/201401-xss-otrs.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00030.html
- http://packetstormsecurity.com/files/131654/OTRS-3.x-Cross-Site-Scripting.htmlExploit
- http://secunia.com/advisories/57018Vendor Advisory
- http://www.osvdb.org/103781
- http://www.securityfocus.com/bid/65844
- https://www.exploit-db.com/exploits/36842/Exploit
- https://www.otrs.com/security-advisory-2014-03-xss-issueVendor Advisory
- http://adamziaja.com/poc/201401-xss-otrs.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00030.html
- http://packetstormsecurity.com/files/131654/OTRS-3.x-Cross-Site-Scripting.htmlExploit
- http://secunia.com/advisories/57018Vendor Advisory
- http://www.osvdb.org/103781
- http://www.securityfocus.com/bid/65844
- https://www.exploit-db.com/exploits/36842/Exploit
- https://www.otrs.com/security-advisory-2014-03-xss-issueVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.