CVE-2022-32074: XSS
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-32074?
CVE-2022-32074 is a stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS.
How does CVE-2022-32074 affect osTicket?
CVE-2022-32074 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
What is the severity of CVE-2022-32074?
CVE-2022-32074 has a severity rating of medium, with a severity value of 5.4.
How can I fix CVE-2022-32074?
To fix CVE-2022-32074, update osTicket-plugins - Storage-FS to commit a7842d494889fd5533d13deb3c6a7789768795ae or later.
Where can I find more information about XSS vulnerabilities?
You can find more information about XSS vulnerabilities on the OWASP website: https://owasp.org/www-community/attacks/xss/