4.3
CVSSv2

CVE-2017-9299

Published: 29/05/2017 Updated: 24/11/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20 release, for example, is not affected.

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs 3.3.9

Vendor Advisories

Debian Bug report logs - #864319 CVE-2017-9324 Package: otrs; Maintainer for otrs is Patrick Matthäi <pmatthaei@debianorg>; Source for otrs is src:otrs2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 6 Jun 2017 20:39:01 UTC Severity: grave Tags: fixed-upstream, security, upstrea ...