CVE-2020-1766

medium

Description

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

References

https://otrs.com/release-notes/otrs-security-advisory-2020-02/

https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html

https://lists.debian.org/debian-lts-announce/2020/01/msg00027.html

http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html

http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html

http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html

Details

Source: Mitre, NVD

Published: 2020-01-10

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium