CVE Vulnerabilities

CVE-2024-43442

Improper Filtering of Special Elements

Published: Aug 26, 2024 | Modified: Aug 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Improper Neutralization of Input done by an attacker with admin privileges (Cross-site Scripting) in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects: 

  • OTRS from 7.0.X through 7.0.50
  • OTRS 8.0.X
  • OTRS 2023.X
  • OTRS from 2024.X through 2024.5.X
  • ((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Weakness

The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.

References