Candidate: CVE-2017-9299 PublicDate: 2017-05-29 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9299 http://code610.blogspot.com/2017/05/turnkey-feat-otrs.html Description: Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20 release, for example, is not affected. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_otrs2: upstream_otrs2: released (3.3.20) precise/esm_otrs2: DNE trusty_otrs2: ignored (reached end-of-life) trusty/esm_otrs2: DNE (trusty was needed) vivid/stable-phone-overlay_otrs2: DNE vivid/ubuntu-core_otrs2: DNE xenial_otrs2: not-affected (5.0.7-1) yakkety_otrs2: ignored (reached end-of-life) zesty_otrs2: ignored (reached end-of-life) artful_otrs2: ignored (reached end-of-life) bionic_otrs2: not-affected (5.0.7-1) cosmic_otrs2: not-affected (5.0.7-1) disco_otrs2: not-affected (5.0.7-1) devel_otrs2: not-affected (5.0.7-1)