SB2019031322 - Code Injection in OTRS



SB2019031322 - Code Injection in OTRS

Published: March 13, 2019 Updated: April 1, 2021

Security Bulletin ID SB2019031322
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Code Injection (CVE-ID: CVE-2019-9752)

The vulnerability allows a remote authenticated user to execute arbitrary code.

An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Modules/PictureUpload.pm.


Remediation

Install update from vendor's website.