Back to Database
Status published
Low
CVE-2010-4071
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4071
Credits & Attribution
No credits recorded in the NVD database.
References
More from otrs
View All →CVE-2019-9892
An issue was discovered in Open Ticket Request System (OTRS)...
Medium
6.5
CVE-2019-9753
An issue was discovered in Open Ticket Request System (OTRS)...
Low
3.5
CVE-2019-9752
An issue was discovered in Open Ticket Request System (OTRS)...
Medium
5.4
CVE-2019-9751
An issue was discovered in Open Ticket Request System (OTRS)...
Medium
4.8
CVE-2019-18180
Denial of service
Medium
5.3
Affected Vendor
otrs
View all reports →Affected Software
otrs
Vulnerable Versions:
2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8
Timeline
Official Publish:
January 20th, 2011
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.