CVE Vulnerabilities

CVE-2019-12248

Published: Jun 17, 2019 | Modified: Aug 31, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.

Affected Software

Name Vendor Start Version End Version
Otrs Otrs 5.0.0 (including) 5.0.36 (including)
Otrs Otrs 6.0.0 (including) 6.0.19 (including)
Otrs Otrs 7.0.0 (including) 7.0.7 (including)
Otrs2 Ubuntu bionic *
Otrs2 Ubuntu cosmic *
Otrs2 Ubuntu disco *
Otrs2 Ubuntu esm-apps/bionic *
Otrs2 Ubuntu esm-apps/xenial *
Otrs2 Ubuntu trusty *
Otrs2 Ubuntu upstream *
Otrs2 Ubuntu xenial *

References