First published: Mon Sep 05 2022(Updated: )
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.0<=6.0.32 | |
Otrs Otrs | >=7.0.0<7.0.37 | |
Otrs Otrs | >=8.0.0<8.0.25 |
Update to OTRS 7.0.37 or OTRS 8.0.25.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-39049.
The severity of CVE-2022-39049 is medium with a CVSS score of 4.8.
CVE-2022-39049 affects OTRS versions 6.0.0 to 6.0.32, 7.0.0 to 7.0.37, and 8.0.0 to 8.0.25.
The impact of CVE-2022-39049 is that an attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
To fix CVE-2022-39049, it is recommended to update OTRS to a version that is not affected by this vulnerability.