CVE-2017-9299

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-9299
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9299.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-9299
Downstream
Withdrawn
2025-04-03T03:58:15.702507Z
Published
2017-05-29T19:29:00Z
Modified
2025-01-14T07:19:32.226172Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20 release, for example, is not affected.

References

Affected packages

Git / github.com/otrs/otrs

Affected ranges

Type
GIT
Repo
https://github.com/otrs/otrs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

rel-1_0_0-RC1
rel-1_0_0-RC2
rel-1_0_0-RC3
rel-1_0_0_rc1
rel-1_0_0_rc2
rel-1_0_0_rc3
rel-1_1_0-RC1
rel-1_1_0-RC2
rel-1_1_0_rc1
rel-1_1_0_rc2
rel-1_2_0-b1
rel-1_2_0-b2
rel-1_2_0-b3
rel-1_2_0_beta1
rel-1_2_0_beta2
rel-1_2_0_beta3
rel-1_2_1
rel-2_0_0-b1
rel-2_0_0_beta1
rel-2_0_1
rel-2_0_2
rel-2_0_3
rel-2_1_0-b1
rel-2_1_0-b2
rel-2_1_0_beta1
rel-2_1_0_beta2
rel-2_1_1
rel-2_1_2
rel-2_1_3
rel-2_2_0-b1
rel-2_2_0-b2
rel-2_2_0-b3
rel-2_2_0-b4
rel-2_2_0_beta1
rel-2_2_0_beta2
rel-2_2_0_beta3
rel-2_2_0_beta4
rel-2_2_1
rel-2_2_2
rel-2_3_1
rel-2_3_2
rel-2_4_0-b2
rel-2_4_0-b3
rel-2_4_0-b4
rel-2_4_0-b6
rel-2_4_0_beta2
rel-2_4_0_beta3
rel-2_4_0_beta4
rel-2_4_0_beta6
rel-2_4_1
rel-2_4_2
rel-2_4_3
rel-2_4_4
rel-3_0_0-b2
rel-3_0_0-b3
rel-3_0_0-b4
rel-3_0_0-b5
rel-3_0_0-b7
rel-3_0_0_beta2
rel-3_0_0_beta3
rel-3_0_0_beta4
rel-3_0_0_beta5
rel-3_0_0_beta7
rel-3_0_1
rel-3_0_2
rel-3_0_3
rel-3_0_4
rel-3_1_0-b1
rel-3_1_0-b3
rel-3_1_0-b4
rel-3_1_0-b5
rel-3_1_0-rc1
rel-3_1_0_beta1
rel-3_1_0_beta3
rel-3_1_0_beta4
rel-3_1_0_beta5
rel-3_1_0_rc1
rel-3_1_2
rel-3_1_4
rel-3_2_0_beta1
rel-3_2_0_beta2
rel-3_2_0_beta3
rel-3_2_0_beta4
rel-3_2_0_beta5
rel-3_2_0_rc1
rel-3_2_1
rel-3_2_2
rel-3_2_3
rel-3_2_4
rel-3_3_0_beta1
rel-3_3_0_beta2
rel-3_3_0_beta3
rel-3_3_0_beta4
rel-3_3_0_beta5
rel-3_3_0_rc1
rel-3_3_1
rel-3_3_2
rel-3_3_3
rel-3_3_4
rel-3_3_5
rel-3_3_6
rel-3_3_7
rel-3_3_8
rel-3_3_9