5.8

CVE-2005-3895

Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML.  NOTE: this particular issue is referred to as XSS by some sources.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OtrsOtrs Version1.0.0
OtrsOtrs Version1.3.2
OtrsOtrs Version2.0.0
OtrsOtrs Version2.0.1
OtrsOtrs Version2.0.2
OtrsOtrs Version2.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.27% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N