<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>24419</bug_id>
          
          <creation_ts>2010-10-25 15:56:54 +0400</creation_ts>
          <short_desc>AgentTicketZoom is vulnerable to XSS attacks from HTML e-mails</short_desc>
          <delta_ts>2010-10-29 09:26:17 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>otrs</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://otrs.org/advisory/OSA-2010-03-en/</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Sergey Y. Afonin">asy</assigned_to>
          <cc>asy</cc>
    
    <cc>zidex</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>114247</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2010-10-25 15:56:54 +0400</bug_when>
    <thetext>Whenever a customer sends an HTML e-mail and RichText is enabled in OTRS, javascript contained in the email can do everything in the OTRS agent interface that the agent himself could do.
Most relevant is that this type of exploit can be used in such a way that the agent won&apos;t even detect he is being exploited.
Affected by this vulnerability are all releases of OTRS 2.4.x up to and including 2.4.8.

This vulnerability is fixed in OTRS 2.4.9.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>114265</commentid>
    <comment_count>1</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-10-25 21:36:37 +0400</bug_when>
    <thetext>otrs-2.4.9-alt1 -&gt; sisyphus:

* Mon Oct 25 2010 Pavel Zilke &lt;zidex at altlinux&gt; 2.4.9-alt1
- Security fixes:
  + AgentTicketZoom is vulnerable to XSS attacks from HTML e-mails; OSA-2010-03 (ALT #24419)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>