PT-2022-4661 · Otrs+1 · Otrs+1

Aleksey Solovev

·

Published

2021-09-29

·

Updated

2024-08-06

·

CVE-2022-39050

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OTRS (affected versions not specified)
Description The issue allows an attacker logged in as an admin user to manipulate the customer URL field, storing JavaScript code that can be executed later by any agent when clicking the customer URL link. This stored JavaScript is executed in the context of OTRS. A similar issue applies to the use of external data sources, such as databases or LDAP. The vulnerability is related to the lack of protection of the web page structure, which can allow a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations For all affected versions, consider disabling the ability to store and execute JavaScript code in the customer URL field as a temporary workaround until a patch is available. Restrict access to external data sources, such as databases or LDAP, to minimize the risk of exploitation. Avoid using the customer URL field until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2917
ALT-PU-2021-3039
ALT-PU-2021-3058
ALT-PU-2024-10583
BDU:2022-05546
CVE-2022-39050

Affected Products

Alt Linux
Otrs