Описание
OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.10:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.11:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.13:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.14:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.15:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.16:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.17:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.18:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.19:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.1.20:*:*:*:*:*:*:*
Конфигурация 3
Одно из
cpe:2.3:a:otrs:otrs:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.0:beta3:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.0:beta4:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.0:beta5:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.10:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.11:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.12:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.13:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.14:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.2.15:*:*:*:*:*:*:*
Конфигурация 4
Одно из
cpe:2.3:a:otrs:otrs:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.0:beta4:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.0:beta5:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:3.3.5:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00226
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
ubuntu
почти 12 лет назад
OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.
debian
почти 12 лет назад
OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 ...
github
больше 3 лет назад
OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.
EPSS
Процентиль: 45%
0.00226
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-20