Description
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1816-1 | otrs2 security update |
Debian DLA |
DLA-1877-1 | otrs2 security update |
Debian DLA |
DLA-3551-1 | otrs2 security update |
EUVD |
EUVD-2019-3890 | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:17:39.008Z
Reserved: 2019-05-21T00:00:00.000Z
Link: CVE-2019-12248
No data.
Status : Modified
Published: 2019-06-17T18:15:10.860
Modified: 2024-11-21T04:22:28.797
Link: CVE-2019-12248
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD