Vulnerability Description
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | <= 2.4.6 |
Related Weaknesses (CWE)
References
- http://bugs.otrs.org/show_bug.cgi?id=4818Exploit
- http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807
- http://bugs.otrs.org/show_bug.cgi?id=4818Exploit
- http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807
FAQ
What is CVE-2010-4766?
CVE-2010-4766 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially s...
How severe is CVE-2010-4766?
CVE-2010-4766 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-4766?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs.