CVE-2018-11563: Medium severity otrs vulnerability
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS customer panel application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11563?
CVE-2018-11563 has been classified as a critical vulnerability due to its potential for remote code execution through crafted emails.
How do I fix CVE-2018-11563?
To fix CVE-2018-11563, you should upgrade your OTRS installation to version 6.0.8 or later.
Which versions of OTRS are affected by CVE-2018-11563?
CVE-2018-11563 affects OTRS versions from 6.0.0 to 6.0.7 inclusive.
Can CVE-2018-11563 affect Debian systems?
Yes, CVE-2018-11563 can affect Debian systems that have the vulnerable version of OTRS installed.
What impact does CVE-2018-11563 have on users?
CVE-2018-11563 allows attackers to execute arbitrary code in the context of logged-in users' browsers, compromising user data and session integrity.