CVE-2007-2524
otrs2
EPSS 5.8%
Description
Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.
How to fix CVE-2007-2524
To remediate CVE-2007-2524, upgrade the affected package to a fixed version below.
- Debian/otrs2—upgrade to 2.1.1-1 or later
- Debian/otrs2—upgrade to 2.0.4p01-17 or later
Is CVE-2007-2524 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.1.1-1
- from 0, < 2.0.4p01-17