lists.opensuse.org
http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.html CVE-2013-2637
MEDIUM
OTRS 3.x - FAQ Module Persistent Cross-Site Scripting
Record summary
CVE-2013-2637 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOTRS 3.x - FAQ Module Persistent Cross-Site ScriptingExploitDB exploitby Luigi VezzosoNot analyzed1 file
References
5exploit-db.com
http://www.exploit-db.com/exploits/24922 securityfocus.com
http://www.securityfocus.com/bid/58930 exchange.xforce.ibmcloud.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/83288 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-2637