CVE-2019-9752

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-9752
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9752.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-9752
Downstream
Related
Published
2019-03-13T22:29:00Z
Modified
2024-11-21T04:52:14Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Modules/PictureUpload.pm.

References

Affected packages