Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m47-2rpp-v9mw

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.

The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.

EPSS

Процентиль: 46%
0.00233
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 15 лет назад

The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.

nvd
почти 15 лет назад

The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.

debian
почти 15 лет назад

The AgentTicketForward feature in Open Ticket Request System (OTRS) be ...

EPSS

Процентиль: 46%
0.00233
Низкий

Дефекты

CWE-20