Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
[
{
"events": [
{
"introduced": "5.0.0"
},
{
"last_affected": "5.0.39"
}
]
},
{
"events": [
{
"introduced": "6.0.0"
},
{
"last_affected": "6.0.24"
}
]
},
{
"events": [
{
"introduced": "7.0.0"
},
{
"last_affected": "7.0.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-1766.json"