An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Modules/PictureUpload.pm.
| Software | From | Fixed in |
|---|---|---|
| otrs / otrs | 5.0.0 | 5.0.34 |
| otrs / otrs | 6.0.0 | 6.0.16 |
| otrs / otrs | 7.0.0 | 7.0.4 |
| opensuse / leap | 15.1 | 15.1.x |
| opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
| opensuse / leap | 15.2 | 15.2.x |
| opensuse / backports_sle | 15.0-sp2 | 15.0-sp2.x |