Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g24f-94pq-jr67

Опубликовано: 26 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects: 

  • OTRS from 7.0.X through 7.0.50
  • OTRS 8.0.X
  • OTRS 2023.X
  • OTRS from 2024.X through 2024.5.X
  • ((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects: 

  • OTRS from 7.0.X through 7.0.50
  • OTRS 8.0.X
  • OTRS 2023.X
  • OTRS from 2024.X through 2024.5.X
  • ((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

EPSS

Процентиль: 23%
0.00077
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-79
CWE-790

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 1 года назад

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

CVSS3: 4.9
nvd
больше 1 года назад

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:  * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

CVSS3: 4.9
fstec
больше 1 года назад

Уязвимость системы обработки заявок OTRS, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 23%
0.00077
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-79
CWE-790