CVE-2013-2637
12.02.2020, 17:15
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
Vendor | Product | Version |
---|---|---|
otrs | faq | 𝑥 < 2.0.8 |
otrs | faq | 2.1.0 ≤ 𝑥 < 2.1.4 |
otrs | otrs_itsm | 𝑥 < 3.0.7 |
otrs | otrs_itsm | 3.1.0 ≤ 𝑥 < 3.1.8 |
otrs | otrs_itsm | 3.2.0 ≤ 𝑥 < 3.2.4 |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
𝑥
= Vulnerable software versions
References