PT-2022-13200 · Otrs Ag · Otrs

Balázs Úr

·

Published

2022-03-21

·

Updated

2022-03-28

·

CVE-2022-0475

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OTRS AG OTRS versions 7.0.0 through 7.0.32 OTRS AG OTRS versions 8.0.0 through 8.0.19
Description A malicious translator can inject JavaScript code into translatable strings where HTML is allowed. This code can be executed in the Package manager.
Recommendations For OTRS AG OTRS versions 7.0.0 through 7.0.32, update to a version later than 7.0.32 to resolve the issue. For OTRS AG OTRS versions 8.0.0 through 8.0.19, update to a version later than 8.0.19 to resolve the issue. As a temporary workaround, consider restricting the ability to inject JavaScript code into translatable strings until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0475

Affected Products

Otrs