CVE-2022-39050: Possible XSS stored in customer information
An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-39050.
What is the severity of CVE-2022-39050?
The severity of CVE-2022-39050 is medium with a CVSS score of 4.8.
What software is affected by CVE-2022-39050?
This vulnerability affects OTRS versions 6.0.0 to 6.0.32, 7.0.0 to 7.0.37, and 8.0.0 to 8.0.25.
What is the impact of CVE-2022-39050?
An attacker who is logged into OTRS as an admin user can manipulate the customer URL field to store JavaScript code which will be executed when other agents click the customer URL link, allowing unauthorized code execution in the context of OTRS.
How can I fix CVE-2022-39050?
Apply the latest security update provided by OTRS to fix this vulnerability.