CVE-2018-11563

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/07/2019
Last modified:
31/01/2023

Description

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS customer panel application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.7 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*