VDB
CVE-2010-4071
CVE-2010-4071
PUBLISHED
CVSS 2.5999999046325684 LOW
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.
EPSS 0.45% · 64.0th percentile
Risk Scores
CVSS 2.0
2.5999999046325684
EPSS Score
0.45%
64.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| otrs | otrs | 2.4.1, 2.4.2, 2.4.4 |
Timeline
- Jan 20, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 68882 vdb
- 41978 third-party-advisory
- http://bugs.gentoo.org/342687 url
- http://otrs.org/advisory/OSA-2010-03-en/ url
- SUSE-SR:2010:024 vendor-advisory
- http://www.vuxml.org/freebsd/96e776c7-e75c-11df-8f26-00151735203a.html url
- https://nvd.nist.gov/vuln/detail/CVE-2010-4071 advisory
- http://otrs.org/advisory/OSA-2010-03-en url