LWN.net Logo

otrs: cross-site scripting

Package(s):otrs CVE #(s):CVE-2012-4600
Created:September 19, 2012 Updated:September 19, 2012
Description: From the CVE entry:

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.

Alerts:
openSUSE openSUSE-SU-2012:1214-1 2012-09-19
Mageia MGASA-2012-0322 2012-11-06
Mandriva MDVSA-2013:112 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds