Description
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
No analysis available yet.
Remediation
Vendor Solution
Update to OTRS 7.0.37 or OTRS 8.0.25.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-41595 | An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. |
References
History
Mon, 16 Sep 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Possible XSS in Admin Interface | Possible XSS in Admin Interface |
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-16T23:10:38.532Z
Reserved: 2022-08-31T00:00:00.000Z
Link: CVE-2022-39049
No data.
Status : Modified
Published: 2022-09-05T07:15:07.980
Modified: 2024-11-21T07:17:27.197
Link: CVE-2022-39049
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD