Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins.
This issue affects:
* OTRS from 7.0.X through 7.0.50
* OTRS 8.0.X
* OTRS 2023.X
* OTRS from 2024.X through 2024.5.X
* ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 26 Aug 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected | |
Title | Stored XSS in process management | |
Weaknesses | CWE-790 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: OTRS
Published: 2024-08-26T08:42:55.095Z
Updated: 2024-08-26T14:55:57.618Z
Reserved: 2024-08-13T13:38:47.972Z
Link: CVE-2024-43443
Vulnrichment
Updated: 2024-08-26T14:55:52.139Z
NVD
Status : Awaiting Analysis
Published: 2024-08-26T09:15:04.573
Modified: 2024-08-26T12:47:20.187
Link: CVE-2024-43443
Redhat
No data.