Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
2018-11-11T05:29:00.290
2024-11-21T03:57:24.780
Modified
CVSSv3.0: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | otrs | open_ticket_request_system | < 4.0.33 | Yes |
Application | otrs | open_ticket_request_system | < 5.0.31 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |