CVE-2019-16375
An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body.
Does this matter?
Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent composes an answer to the original article.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- otrs/otrs
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://community.otrs.com/category/security-advisories-en/Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://otrs.com/release-notes/otrs-security-advisory-2019-13/Release Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://community.otrs.com/category/security-advisories-en/Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://otrs.com/release-notes/otrs-security-advisory-2019-13/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.