SB2021040144 - Input validation error in otrs (Alpine package)



SB2021040144 - Input validation error in otrs (Alpine package)

Published: April 1, 2021

Security Bulletin ID SB2021040144
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2019-12248)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.


Remediation

Install update from vendor's website.