Vulnerability Description
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | >= 5.0.0, <= 5.0.36 |
| Debian | Debian Linux | 8.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://lists.debian.org/debian-lts-announce/2019/06/msg00004.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://www.otrs.com/category/release-and-security-notes-en/Release NotesThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://lists.debian.org/debian-lts-announce/2019/06/msg00004.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://www.otrs.com/category/release-and-security-notes-en/Release NotesThird Party Advisory
FAQ
What is CVE-2019-12248?
CVE-2019-12248 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious...
How severe is CVE-2019-12248?
CVE-2019-12248 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12248?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs, Debian Debian Linux.