| ID | ZSA-2012-03 |
| Date | 2012-10-16 |
| Title | XSS attack in Firefox and Opera possible |
| Severity | Critical |
| Product | OTRS 3.1.x, OTRS 3.0.x, OTRS 2.4.x |
| Fixed in | OTRS 3.1.11, OTRS 3.0.17, OTRS 2.4.15 |
| URL | http://znuny.com/en/ #!/advisory/ZSA-2012-03 |
| CVE | CVE-2012-4751 |
| VU | VU#603276 |
Do you want to get informed about security issues in OTRS? Subscribe here.
An attacker could trick a logged in user to execute malicious java script code by sending a prepared email into OTRS.
Affected by this vulnerability are all releases of OTRS 2.4.x up to and including 2.4.14, OTRS 3.0.x up to and including 3.0.15, as well as all 3.1.x versions up to and including 3.1.10.
This vulnerability is fixed in OTRS (release of OTRS 3.1.11, OTRS 3.0.17 and OTRS 2.4.15 will be published on 16 Oct 2012).
As workaround you can disable the rich text feature via sys config.
As workaround it is also possible to replace the following files with the fixed version:
OTRS 3.1.x:
OTRS 3.0.x:
OTRS 2.4.x:
Please send information regarding vulnerabilities in OTRS to security @ znuny.com.