vendor:
OTRS Open Technology Real Services
by:
loneferret of Offensive Security
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: OTRS Open Technology Real Services
Affected Version From: 3.1.4
Affected Version To: 3.1.4
Patch Exists: YES
Related CWE: CVE-2012-3286
CPE: a:otrs:otrs
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
OTRS Open Technology Real Services XSS Vulnerability
A Cross-Site Scripting (XSS) vulnerability was discovered in OTRS Open Technology Real Services version 3.1.4. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'Body' parameter. A remote attacker can send a specially crafted request containing malicious HTML and script code to the vulnerable application and execute arbitrary code in the browser of the victim in the context of the vulnerable site. Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials and launch other attacks.
Mitigation:
Update to the latest version of OTRS Open Technology Real Services.