An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1816-1 otrs2 security update
Debian DLA Debian DLA DLA-1877-1 otrs2 security update
Debian DLA Debian DLA DLA-3551-1 otrs2 security update
EUVD EUVD EUVD-2019-3890 An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T23:17:39.008Z

Reserved: 2019-05-21T00:00:00

Link: CVE-2019-12248

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-17T18:15:10.860

Modified: 2024-11-21T04:22:28.797

Link: CVE-2019-12248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.