First published: Mon Jul 08 2019(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS customer panel application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=6.0.0<=6.0.7 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11563 has been classified as a critical vulnerability due to its potential for remote code execution through crafted emails.
To fix CVE-2018-11563, you should upgrade your OTRS installation to version 6.0.8 or later.
CVE-2018-11563 affects OTRS versions from 6.0.0 to 6.0.7 inclusive.
Yes, CVE-2018-11563 can affect Debian systems that have the vulnerable version of OTRS installed.
CVE-2018-11563 allows attackers to execute arbitrary code in the context of logged-in users' browsers, compromising user data and session integrity.