First published: Sat Apr 15 2023(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.0<6.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the OTRS vulnerability is CVE-2018-17883.
The severity of CVE-2018-17883 is medium with a CVSS score of 6.1.
CVE-2018-17883 affects OTRS versions 6.0.x before 6.0.12.
An attacker could send a malicious email link to an OTRS system or an agent, which could cause the execution of JavaScript in the context of OTRS if a logged-in agent opens the link.
To fix CVE-2018-17883, update your OTRS installation to version 6.0.12 or newer.