CVE-2018-19141: XSS
Published Nov 11, 2018
·Updated
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
Affected Software
3 affected components
OTRS Open Ticket Request System>=4.0.0<4.0.33
OTRS Open Ticket Request System>=5.0.0<5.0.31
Debian Debian Linux=8.0
Remediation
Event History
Nov 11, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19141?
CVE-2018-19141 is classified as a high-severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2018-19141?
To fix CVE-2018-19141, upgrade OTRS to version 4.0.33 or 5.0.31 or later.
3
Which versions of OTRS are affected by CVE-2018-19141?
CVE-2018-19141 affects OTRS versions 4.0.x before 4.0.33 and 5.0.x before 5.0.31.
4
What type of attack is possible with CVE-2018-19141?
CVE-2018-19141 allows an admin to conduct a cross-site scripting (XSS) attack.
5
Is CVE-2018-19141 a known security risk in Debian?
Yes, CVE-2018-19141 is acknowledged as a security risk in Debian systems using affected OTRS versions.