Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:  * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
History

Mon, 26 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:  * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
Title Stored XSS in System Configuration
Weaknesses CWE-790
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OTRS

Published: 2024-08-26T08:42:39.842Z

Updated: 2024-08-26T15:27:15.700Z

Reserved: 2024-08-13T13:38:47.972Z

Link: CVE-2024-43442

cve-icon Vulnrichment

Updated: 2024-08-26T15:26:50.788Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-26T09:15:04.340

Modified: 2024-08-26T16:35:12.860

Link: CVE-2024-43442

cve-icon Redhat

No data.