CVE-2016-9139

MEDIUM

OTRS <3.3.16, <4.0.19, <5.0.14 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (50)

otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
... and 35 more

Timeline

Published Feb 17, 2017
Tracked Since Feb 18, 2026