MEDIUM
Possible XSS in Customer user address book
Published Mar 27, 2020
5.4
MEDIUMCVSS 3.1
EPSS 1.03%
Description
Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
Affected products
-
- Version 7.0.xStatusaffectedConstraints<=7.0.15
- Version
-
- Version 6.0.xStatusaffectedConstraints<=6.0.26
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to OTRS 7.0.16, ((OTRS)) Community Edition 6.0.27
Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/2576830053f70a3a9251558e55f34843dec61aa2
Weaknesses (1)
References (6)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html vendor-advisoryBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html vendor-advisoryBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html vendor-advisoryBroken Link
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12597 Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html mailing-list
- https://otrs.com/release-notes/otrs-security-advisory-2020-08/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | vendor-advisoryBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | vendor-advisoryBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | vendor-advisoryBroken Link | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12597 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | mailing-list | |
| https://otrs.com/release-notes/otrs-security-advisory-2020-08/ | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OTRS
Published Mar 27, 2020
Updated Sep 17, 2024
Reserved Nov 29, 2019
Link CVE-2020-1771
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-12597 Assigner OTRS
Published Mar 27, 2020
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2020-12597