OTRS Email Body CVE-2012-4600 HTML Injection Vulnerability
BID:55328
Info
OTRS Email Body CVE-2012-4600 HTML Injection Vulnerability
| Bugtraq ID: | 55328 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4600 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2012 12:00AM |
| Updated: | Mar 19 2015 08:27AM |
| Credit: | Mike Eduard of Znuny GmbH |
| Vulnerable: |
OTRS OTRS 3.0.10 OTRS OTRS 3.0.7 OTRS OTRS 3.0.6 OTRS OTRS 3.0.5 OTRS OTRS 2.4.11 OTRS OTRS 2.4.10 OTRS OTRS 2.4.9 OTRS OTRS 2.4.8 OTRS OTRS 2.4.7 OTRS OTRS 2.4.6 OTRS OTRS 2.4.5 OTRS OTRS 2.4.4 OTRS OTRS 2.4.3 OTRS OTRS 2.4.2 OTRS OTRS 3.1.9 OTRS OTRS 3.1.4 OTRS OTRS 3.0.4 OTRS OTRS 3.0.3 OTRS OTRS 3.0.2 OTRS OTRS 3.0.15 OTRS OTRS 3.0.1 OTRS OTRS 2.4.13 OTRS OTRS 2.4.1 |
| Not Vulnerable: |
OTRS OTRS 3.1.10 OTRS OTRS 3.0.16 OTRS OTRS 2.4.14 |
Discussion
OTRS Email Body CVE-2012-4600 HTML Injection Vulnerability
OTRS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
The following versions are vulnerable:
OTRS 2.4.x versions prior to 2.4.14
OTRS 3.0.x versions prior to 3.0.16
OTRS 3.1.x versions prior to 3.1.10
OTRS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
The following versions are vulnerable:
OTRS 2.4.x versions prior to 2.4.14
OTRS 3.0.x versions prior to 3.0.16
OTRS 3.1.x versions prior to 3.1.10
Solution / Fix
OTRS Email Body CVE-2012-4600 HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
OTRS Email Body CVE-2012-4600 HTML Injection Vulnerability
References:
References: