Bug ID 1129756
Summary VUL-1: CVE-2019-9752: otrs: attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/226352/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee chris@computersalat.de
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2019-9752

An issue was discovered in Open Ticket Request System (OTRS) 5.x before
5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged
into OTRS as an agent or a customer user may upload a carefully crafted
resource in order to cause execution of JavaScript in the context of OTRS.
This is related to Content-type mishandling in
Kernel/Modules/PictureUpload.pm.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-9752
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-9752.html


You are receiving this mail because: