AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-3895

MEDIUM · CVSS 5.8 EPSS 2.05%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-11-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2005-3895
Severity
MEDIUM
CVSS
5.8
EPSS
2.05%

Original NVD Description

Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.