First published: Wed Mar 13 2019(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to Kernel/Output/Template/Document.pm.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=6.0.0<6.0.17 | |
OTRS | >=7.0.0<7.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9751 is considered a medium severity vulnerability.
To fix CVE-2019-9751, upgrade to OTRS version 6.0.17 or 7.0.5 or later.
CVE-2019-9751 affects OTRS versions 6.x prior to 6.0.17 and 7.x prior to 7.0.5.
CVE-2019-9751 is a cross-site scripting (XSS) vulnerability.
An attacker logged in as an admin user can manipulate the URL to execute JavaScript in the context of OTRS.