Логотип exploitDog
bind:CVE-2022-39050
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39050

Количество 4

Количество 4

ubuntu логотип

CVE-2022-39050

больше 3 лет назад

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2022-39050

больше 3 лет назад

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-x46q-hjvj-45vc

больше 3 лет назад

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVSS3: 4.8
EPSS: Низкий
fstec логотип

BDU:2022-05546

больше 3 лет назад

Уязвимость системы запроса билетов OTRS, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-39050

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVSS3: 4.6
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-39050

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVSS3: 4.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-x46q-hjvj-45vc

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05546

Уязвимость системы запроса билетов OTRS, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 4.6
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу