Record summary

CVE-2013-2637 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOTRS 3.x - FAQ Module Persistent Cross-Site ScriptingExploitDB exploitby Luigi VezzosoNot analyzed1 file
ExploitDB

PoC details

References

5