Input validation error in OTRS - CVE-2018-16586

 

Input validation error in OTRS - CVE-2018-16586

Published: September 28, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31198
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16586
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image or CSS resources.


Affected software

OTRS
otrs (Alpine package)
Opensuse
SUSE Linux

How to mitigate CVE-2018-16586

Install update from vendor's website.

OTRS - update to 6.0.11
otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins