Candidate: CVE-2020-1771 PublicDate: 2020-03-27 13:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1771 https://otrs.com/release-notes/otrs-security-advisory-2020-08/ Description: Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. Ubuntu-Description: Notes: sbeattie> probably does not affect otrs v5 Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_otrs2: upstream: https://github.com/OTRS/otrs/commit/2576830053f70a3a9251558e55f34843dec61aa2 upstream_otrs2: needs-triage precise/esm_otrs2: DNE trusty_otrs2: ignored (out of standard support) trusty/esm_otrs2: DNE xenial_otrs2: ignored (end of standard support, was needs-triage) bionic_otrs2: needs-triage eoan_otrs2: ignored (reached end-of-life) focal_otrs2: needs-triage groovy_otrs2: not-affected (6.0.27-1) hirsute_otrs2: not-affected (6.0.27-1) impish_otrs2: not-affected (6.0.27-1) jammy_otrs2: not-affected (6.0.27-1) devel_otrs2: not-affected (6.0.27-1)