CVE-2010-4762: XSS
Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4762?
CVE-2010-4762 is classified as a medium severity vulnerability due to its potential impact on user data integrity through cross-site scripting.
How do I fix CVE-2010-4762?
To mitigate CVE-2010-4762, update to OTRS version 3.0.0-beta2 or later, which addresses this vulnerability.
What systems are affected by CVE-2010-4762?
CVE-2010-4762 affects multiple versions of Open Ticket Request System (OTRS) prior to 3.0.0-beta2.
Can CVE-2010-4762 be exploited by unauthenticated users?
No, CVE-2010-4762 requires remote authenticated users to exploit the vulnerability.
What component of OTRS is vulnerable in CVE-2010-4762?
The vulnerability in CVE-2010-4762 lies within the rich-text-editor component of OTRS.