CVE-2013-2637: Opensuse
Medium severity, CVSS 6.1. EPSS: 4.3% chance of exploitation in the next 30 days.
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
Affected products
- Opensuse Opensuse: version 12.2 only; version 12.3 only
- Otrs Faq: before 2.0.8 (fixed in 2.0.8); from 2.1.0, before 2.1.4 (fixed in 2.1.4)
- Otrs Otrs Itsm: before 3.0.7 (fixed in 3.0.7); from 3.1.0, before 3.1.8 (fixed in 3.1.8); from 3.2.0, before 3.2.4 (fixed in 3.2.4)
Published 2020-02-12. Last modified 2026-06-16.