Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins.
This issue affects:
* OTRS from 7.0.X through 7.0.50
* OTRS 8.0.X
* OTRS 2023.X
* OTRS from 2024.X through 2024.5.X
* ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
ssvc
|
Mon, 26 Aug 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected | |
Title | Stored XSS in System Configuration | |
Weaknesses | CWE-790 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: OTRS
Published: 2024-08-26T08:42:39.842Z
Updated: 2024-08-26T15:27:15.700Z
Reserved: 2024-08-13T13:38:47.972Z
Link: CVE-2024-43442
Vulnrichment
Updated: 2024-08-26T15:26:50.788Z
NVD
Status : Awaiting Analysis
Published: 2024-08-26T09:15:04.340
Modified: 2024-08-26T16:35:12.860
Link: CVE-2024-43442
Redhat
No data.