CVE-2018-17883: XSS
Published Apr 15, 2023
·Updated
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.
Affected Software
1 affected component
OTRS OTRS>=6.0.0<6.0.12
Remediation
Event History
Apr 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 16, 2023
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the OTRS vulnerability?
The vulnerability ID of the OTRS vulnerability is CVE-2018-17883.
2
What is the severity of CVE-2018-17883?
The severity of CVE-2018-17883 is medium with a CVSS score of 6.1.
3
How does CVE-2018-17883 affect Open Ticket Request System (OTRS)?
CVE-2018-17883 affects OTRS versions 6.0.x before 6.0.12.
4
What can an attacker do with CVE-2018-17883?
An attacker could send a malicious email link to an OTRS system or an agent, which could cause the execution of JavaScript in the context of OTRS if a logged-in agent opens the link.
5
How can I fix CVE-2018-17883?
To fix CVE-2018-17883, update your OTRS installation to version 6.0.12 or newer.