Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-38057

Опубликовано: 24 июл. 2023
Источник: nvd
CVSS3: 4.1
CVSS3: 5.4
EPSS Низкий

Описание

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:otrs:survey:*:*:*:*:community:*:*:*
Версия от 6.0.0 (включая) до 6.0.22 (включая)
cpe:2.3:a:otrs:survey:*:*:*:*:-:*:*:*
Версия от 7.0.0 (включая) до 7.0.32 (исключая)
cpe:2.3:a:otrs:survey:*:*:*:*:-:*:*:*
Версия от 8.0.0 (включая) до 8.0.13 (исключая)

EPSS

Процентиль: 51%
0.00284
Низкий

4.1 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 4.1
ubuntu
больше 2 лет назад

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

CVSS3: 4.1
github
больше 2 лет назад

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

EPSS

Процентиль: 51%
0.00284
Низкий

4.1 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-79