vendor:
OTRS Open Technology Real Services
by:
Mike Eduard - Znuny - Enterprise Services for OTRS
7,5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: OTRS Open Technology Real Services
Affected Version From: 3.1.8
Affected Version To: 3.1.9
Patch Exists: YES
Related CWE: 2012-4600
CPE: a:otrs:otrs
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2, Open SUSE 12.1, Windows 7 Pro SP1 (x86), Firefox 14, Opera 12.01
2012
OTRS Open Technology Real Services Cross-Site Scripting Vulnerability
OTRS Open Technology Real Services versions 3.1.8 and 3.1.9 are vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can exploit this vulnerability by sending a malicious HTML email containing a specially crafted payload to a victim. The payload is then executed in the victim's browser, allowing the attacker to gain access to the victim's session and potentially execute arbitrary code.
Mitigation:
The vendor has released a patch to address this vulnerability.