OTRS Help Desk CVE-2014-1695 HTML Injection Vulnerability
BID:65844
Info
OTRS Help Desk CVE-2014-1695 HTML Injection Vulnerability
| Bugtraq ID: | 65844 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1695 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2014 12:00AM |
| Updated: | Mar 17 2014 02:04AM |
| Credit: | Adam Ziaja |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OTRS Help Desk CVE-2014-1695 HTML Injection Vulnerability
OTRS Help Desk is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, or to control how the site is rendered to the user. Other attacks are also possible.
Versions OTRS Help Desk prior to 3.1.20, 3.2.15, and 3.3.5 are vulnerable.
OTRS Help Desk is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, or to control how the site is rendered to the user. Other attacks are also possible.
Versions OTRS Help Desk prior to 3.1.20, 3.2.15, and 3.3.5 are vulnerable.
Exploit / POC
OTRS Help Desk CVE-2014-1695 HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
OTRS Help Desk CVE-2014-1695 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.