CVE-2010-4071

Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.6:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.7:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.4.8:*:*:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () http://bugs.gentoo.org/342687 - () http://bugs.gentoo.org/342687 -
References () http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html -
References () http://otrs.org/advisory/OSA-2010-03-en/ - Vendor Advisory () http://otrs.org/advisory/OSA-2010-03-en/ - Vendor Advisory
References () http://secunia.com/advisories/41978 - Vendor Advisory () http://secunia.com/advisories/41978 - Vendor Advisory
References () http://www.osvdb.org/68882 - () http://www.osvdb.org/68882 -
References () http://www.vuxml.org/freebsd/96e776c7-e75c-11df-8f26-00151735203a.html - () http://www.vuxml.org/freebsd/96e776c7-e75c-11df-8f26-00151735203a.html -

Information

Published : 2011-01-20 19:00

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4071

Mitre link : CVE-2010-4071

CVE.ORG link : CVE-2010-4071


JSON object : View

Products Affected

otrs

  • otrs
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')