« Volver al listado

CVE-2020-1766

Estado: ModificadaMedia (6.1)—

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-1766",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@otrs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 0.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@otrs.com",
      "affectedData": [
        {
          "vendor": "OTRS AG",
          "product": "((OTRS)) Community Edition",
          "versions": [
            {
              "status": "affected",
              "version": "5.0.x version 5.0.39 and prior versions"
            },
            {
              "status": "affected",
              "version": "6.0.x version 6.0.24 and prior versions"
            }
          ]
        },
        {
          "vendor": "OTRS AG",
          "product": "OTRS",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.x version 7.0.13 and prior versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-10T15:15:12.050",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html",
      "tags": [
        "Broken Link"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html",
      "tags": [
        "Broken Link"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html",
      "tags": [
        "Broken Link"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00027.html",
      "tags": [
        "Mailing List",
        "Not Applicable",
        "Third Party Advisory"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html",
      "source": "security@otrs.com"
    },
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2020-02/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00027.html",
      "tags": [
        "Mailing List",
        "Not Applicable",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2020-02/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@otrs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions."
    },
    {
      "lang": "es",
      "value": "Debido al manejo inapropiado de las imágenes cargadas, es posible, en condiciones muy extrañas y poco frecuentes, forzar al navegador de los agentes a ejecutar JavaScript malicioso desde un archivo SVG especial diseñado tal y como un archivo jpg en línea. Este problema afecta a: ((OTRS)) Community Edition versiones 5.0.x versión 5.0.39 y anteriores; versiones 6.0.x versión 6.0.24 y anteriores. OTRS versiones 7.0.x versión 7.0.13 y anteriores."
    }
  ],
  "lastModified": "2026-06-17T03:02:21.620",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "930593FF-E99D-46BB-AABD-9562CC94B8D3",
              "versionEndIncluding": "5.0.39",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69D1FDA1-32D6-4793-AB1D-ED9F0A17939F",
              "versionEndIncluding": "6.0.24",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D86D6CD7-52CC-47B5-8075-462D4A3099FC",
              "versionEndIncluding": "7.0.13",
              "versionStartIncluding": "7.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@otrs.com"
}