Bug ID 1203131
Summary VUL-0: CVE-2022-39050: otrs: Possible XSS stored in customer information
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/341496/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee chris@computersalat.de
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-39050

An attacker who is logged into OTRS as an admin user may manipulate customer
URL
field to store JavaScript code to be run later by any other agent when clicking
the customer URL link. Then the stored JavaScript is executed in the context of
OTRS. The same issue applies for the usage of external data sources e.g.
database or ldap

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39050
https://www.cve.org/CVERecord?id=CVE-2022-39050
https://otrs.com/release-notes/otrs-security-advisory-2022-11/


You are receiving this mail because: