Vulnerability Description
Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | >= 5.0.0, <= 5.0.39 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://lists.debian.org/debian-lts-announce/2020/01/msg00027.htmlMailing ListNot ApplicableThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://otrs.com/release-notes/otrs-security-advisory-2020-02/PatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://lists.debian.org/debian-lts-announce/2020/01/msg00027.htmlMailing ListNot ApplicableThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://otrs.com/release-notes/otrs-security-advisory-2020-02/PatchVendor Advisory
FAQ
What is CVE-2020-1766?
CVE-2020-1766 is a vulnerability with a CVSS score of 2.0 (LOW). Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as ...
How severe is CVE-2020-1766?
CVE-2020-1766 has been rated LOW with a CVSS base score of 2.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1766?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs, Debian Debian Linux.