CVE-2022-39049: Possible XSS in Admin Interface
Published Sep 5, 2022
·Updated
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
Affected Software
3 affected components
OTRS OTRS>=6.0.0<=6.0.32
OTRS OTRS>=7.0.0<7.0.37
OTRS OTRS>=8.0.0<8.0.25
Remediation
Information
Update to OTRS 7.0.37 or OTRS 8.0.25.
Event History
Sep 5, 2022
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-39049.
2
What is the severity of CVE-2022-39049?
The severity of CVE-2022-39049 is medium with a CVSS score of 4.8.
3
How does CVE-2022-39049 affect OTRS?
CVE-2022-39049 affects OTRS versions 6.0.0 to 6.0.32, 7.0.0 to 7.0.37, and 8.0.0 to 8.0.25.
4
What is the impact of CVE-2022-39049?
The impact of CVE-2022-39049 is that an attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
5
How can I fix CVE-2022-39049?
To fix CVE-2022-39049, it is recommended to update OTRS to a version that is not affected by this vulnerability.