CVE-2019-9752

An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Modules/PictureUpload.pm.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*

History

21 Nov 2024, 04:52

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Mailing List, Third Party Advisory
References () https://community.otrs.com/security-advisory-2019-01-security-update-for-otrs-framework - Patch, Vendor Advisory () https://community.otrs.com/security-advisory-2019-01-security-update-for-otrs-framework - Patch, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2019/03/msg00023.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/03/msg00023.html - Mailing List, Third Party Advisory

Information

Published : 2019-03-13 22:29

Updated : 2024-11-21 04:52


NVD link : CVE-2019-9752

Mitre link : CVE-2019-9752

CVE.ORG link : CVE-2019-9752


JSON object : View

Products Affected

opensuse

  • leap
  • backports_sle

otrs

  • otrs
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')