CVE-2019-9751: XSS
Published Mar 13, 2019
·Updated
An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to Kernel/Output/Template/Document.pm.
Affected Software
2 affected components
OTRS OTRS>=6.0.0<6.0.17
OTRS OTRS>=7.0.0<7.0.5
Remediation
Event History
Mar 13, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-9751?
CVE-2019-9751 is considered a medium severity vulnerability.
2
How do I fix CVE-2019-9751?
To fix CVE-2019-9751, upgrade to OTRS version 6.0.17 or 7.0.5 or later.
3
Who is affected by CVE-2019-9751?
CVE-2019-9751 affects OTRS versions 6.x prior to 6.0.17 and 7.x prior to 7.0.5.
4
What type of vulnerability is CVE-2019-9751?
CVE-2019-9751 is a cross-site scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2019-9751?
An attacker logged in as an admin user can manipulate the URL to execute JavaScript in the context of OTRS.