LWN.net Logo

otrs2: cross-site scripting

Package(s):otrs2 CVE #(s):CVE-2012-2582
Created:August 31, 2012 Updated:September 6, 2012
Description: From the Debian advisory:

It was discovered that otrs2, a ticket request system, contains a cross-site scripting vulnerability when email messages are viewed using Internet Explorer. This update also improves the HTML security filter to detect tag nesting.

Alerts:
Debian DSA-2536-1 2012-08-30
openSUSE openSUSE-SU-2012:1105-1 2012-09-04
openSUSE openSUSE-SU-2012:1105-2 2012-09-04
Mageia MGASA-2012-0322 2012-11-06
Mandriva MDVSA-2013:112 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds