CVE-2016-9139
Published: 17 February 2017
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.
Priority
Status
| Package | Release | Status |
|---|---|---|
|
otrs2 Launchpad, Ubuntu, Debian |
artful |
Ignored
(end of life)
|
| bionic |
Not vulnerable
(5.0.14-1)
|
|
| cosmic |
Not vulnerable
(5.0.14-1)
|
|
| disco |
Not vulnerable
(5.0.14-1)
|
|
| eoan |
Not vulnerable
(5.0.14-1)
|
|
| focal |
Not vulnerable
(5.0.14-1)
|
|
| groovy |
Not vulnerable
(5.0.14-1)
|
|
| hirsute |
Not vulnerable
(5.0.14-1)
|
|
| impish |
Not vulnerable
(5.0.14-1)
|
|
| jammy |
Not vulnerable
(5.0.14-1)
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| precise |
Ignored
(end of life)
|
|
| trusty |
Does not exist
(trusty was needed)
|
|
| upstream |
Needs triage
|
|
| xenial |
Needed
|
|
| yakkety |
Ignored
(end of life)
|
|
| zesty |
Ignored
(end of life)
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 6.1 |
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Changed |
| Confidentiality | Low |
| Integrity impact | Low |
| Availability impact | None |
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |