CVE-2018-17883Cross-site Scripting in Otrs

Severity
6.1MEDIUMNVD
EPSS
0.9%
top 24.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 16

Description

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDotrs/otrs6.0.06.0.12
debiandebian/otrs2< otrs2 6.0.12-1 (bullseye)

Patches

🔴Vulnerability Details

2
OSV
CVE-2018-17883: An issue was discovered in Open Ticket Request System (OTRS) 62023-04-16
GHSA
GHSA-2cjf-4qjm-hh7v: An issue was discovered in Open Ticket Request System (OTRS) 62023-04-16

📋Vendor Advisories

1
Debian
CVE-2018-17883: otrs2 - An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12...2018
CVE-2018-17883 — Cross-site Scripting in Otrs | cvebase