OTRS 'Body' Field HTML Injection Vulnerability
BID:54890
Info
OTRS 'Body' Field HTML Injection Vulnerability
| Bugtraq ID: | 54890 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2582 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2012 12:00AM |
| Updated: | Aug 31 2012 05:02PM |
| Credit: | loneferret |
| Vulnerable: |
OTRS OTRS 3.0.10 OTRS OTRS 3.0.7 OTRS OTRS 3.0.6 OTRS OTRS 3.0.5 OTRS OTRS 2.4.11 OTRS OTRS 2.4.10 OTRS OTRS 2.4.10 OTRS OTRS 2.4.9 OTRS OTRS 2.4.8 OTRS OTRS 2.4.8 OTRS OTRS 2.4.7 OTRS OTRS 2.4.6 OTRS OTRS 2.4.5 OTRS OTRS 2.4.4 OTRS OTRS 2.4.3 OTRS OTRS 2.4.2 OTRS OTRS 3.0.4 OTRS OTRS 3.0.3 OTRS OTRS 3.0.2 OTRS OTRS 3.0.1 OTRS OTRS 2.4.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
OTRS 'Body' Field HTML Injection Vulnerability
OTRS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
OTRS 3.1.4 is vulnerable; other versions may also be affected.
OTRS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
OTRS 3.1.4 is vulnerable; other versions may also be affected.
Exploit / POC
OTRS 'Body' Field HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Solution / Fix
OTRS 'Body' Field HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
OTRS 'Body' Field HTML Injection Vulnerability
References:
References: