Description
The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to OTRS 8.0.37 or OTRS 7.0.47
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41885 | The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34. |
References
History
No history.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-16T16:56:26.630Z
Reserved: 2023-07-12T08:05:38.780Z
Link: CVE-2023-38059
Updated: 2024-08-02T17:30:13.552Z
Status : Modified
Published: 2023-10-16T09:15:10.243
Modified: 2024-11-21T08:12:46.270
Link: CVE-2023-38059
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD