VDB
CVE-2019-16375
CVE-2019-16375
PUBLISHED
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent composes an answer to the original article.
EPSS 0.65% · 71.2th percentile
Risk Scores
EPSS Score
0.65%
71.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | otrs2 | 5.0.7-1, 0, 5.0.1-1 |
| Ubuntu:18.04:LTS | otrs2 | 6.0.1-1, 6.0.2-1, 6.0.5-1 |
Exploit Intelligence
- https://community.otrs.com/category/security-advisories-en/ (circl)
- https://otrs.com/release-notes/otrs-security-advisory-2019-13/ (circl)
- openSUSE-SU-2020:0551 (circl)
- openSUSE-SU-2020:1475 (circl)
- openSUSE-SU-2020:1509 (circl)
- [debian-lts-announce] 20230831 [SECURITY] [DLA 3551-1] otrs2 security update (circl)
Timeline
- Oct 3, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-16375 third-party-advisory
- https://community.otrs.com/security-advisory-2019-13-security-update-for-otrs-framework/ third-party-advisory
- https://github.com/OTRS/otrs/commit/aeb33d800716e2a6653597aa86314c4cbdadb678 third-party-advisory
- https://github.com/OTRS/otrs/commit/03ca8f396b1aa9933c212a63f52a9ea26c06e7da third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16375 third-party-advisory