Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open Ticket Request System下载附件执行任意脚本漏洞
Vulnerability Description
OpenTRS是一款免费的开源的订票系统,它具有电子邮件、电话等接口功能。 Open Ticket Request System (OTRS) 1.0.0至1.3.2以及2.0.0至2.0.3中,如果将AttachmentDownloadType设置为内联,则会在队列审阅者尝试下载附件时,将text/html电子邮件附件呈现为浏览器中的HTML,这可让远程攻击者执行任意Web脚本或HTML。 注意:某些消息来源将此特定问题引用为XSS。
CVSS Information
N/A
Vulnerability Type
N/A