Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://znuny.com/en/#%21/advisory/ZSA-2012-02 | |
http://secunia.com/advisories/50615 | third party advisory |
http://www.otrs.com/de/open-source/community-news/security-advisories/security-advisory-2012-02/ | vendor advisory |
http://www.kb.cert.org/vuls/id/511404 | us government resource exploit third party advisory |