A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.html | Mailing List Third Party Advisory |
http://www.exploit-db.com/exploits/24922 | Exploit Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/58930 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/83288 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-12T16:07:19
Updated: 2020-02-12T16:07:19
Reserved: 2013-03-22T00:00:00
Link: CVE-2013-2637
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-12T17:15:11.733
Modified: 2020-02-18T20:11:42.297
Link: CVE-2013-2637
JSON object: View
Redhat Information
No data.
CWE