First published: Tue May 21 2019(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5.0.x through 5.0.12. An attacker who is logged into OTRS as an agent with appropriate permissions may create a carefully crafted calendar appointment in order to cause execution of JavaScript in the context of OTRS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=5.0.0<=5.0.12 | |
OTRS | >=6.0.0<=6.0.17 | |
OTRS | >=7.0.0<=7.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10066 is rated as a high severity vulnerability due to the potential for unauthorized calendar appointments to be created by logged-in agents.
To fix CVE-2019-10066, upgrade your OTRS installation to version 7.0.7 or higher, or to version 6.0.18 or higher.
CVE-2019-10066 affects users of OTRS versions 5.0.x through 5.0.12, 6.0.x through 6.0.17, and 7.x through 7.0.6.
An attacker with agent permissions can exploit CVE-2019-10066 to create a specially crafted calendar appointment that may affect the integrity of the calendar.
There is no official workaround for CVE-2019-10066, and users are encouraged to upgrade to secure versions of OTRS.