LWN.net Logo

otrs: cross-site scripting

Package(s):otrs CVE #(s):CVE-2012-4751
Created:November 7, 2012 Updated:January 23, 2013
Description: From the Mageia advisory:

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with whitespace before a javascript: URL in the SRC attribute of an element, as demonstrated by an IFRAME element.

Alerts:
Mageia MGASA-2012-0322 2012-11-06
openSUSE openSUSE-SU-2013:0145-1 2013-01-23
Mandriva MDVSA-2013:112 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds