SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12248

An attacker could send a malicious email to an OTRS system.

MEDIUM 4.3EPSS 1.56%

Does this matter?

Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
1.56% probability · 74th percentile
CISA KEV
Not listed
Affected
otrs/otrs · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.