Bug ID 1203130
Summary VUL-0: CVE-2022-39049: otrs: An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/341497/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee chris@computersalat.de
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-39049

An attacker who is logged into OTRS as an admin user may manipulate the URL to
cause execution of JavaScript in the context of OTRS.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39049
https://www.cve.org/CVERecord?id=CVE-2022-39049
https://otrs.com/release-notes/otrs-security-advisory-2022-10/


You are receiving this mail because: