CVE-2018-19142Cross-site Scripting in Open Ticket Request System

Severity
4.8MEDIUMNVD
EPSS
0.3%
top 47.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 14

Description

Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

NVDotrs/open_ticket_request_system6.0.06.0.13
debiandebian/otrs2< otrs2 6.0.13-1 (bullseye)

🔴Vulnerability Details

2
GHSA
GHSA-644h-4r83-2cf3: Open Ticket Request System (OTRS) 62022-05-14
OSV
CVE-2018-19142: Open Ticket Request System (OTRS) 62018-11-11

📋Vendor Advisories

1
Debian
CVE-2018-19142: otrs2 - Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct...2018