CVE-2024-43442: Stored XSS in System Configuration
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:
OTRS from 7.0.X through 7.0.50 OTRS 8.0.X OTRS 2023.X OTRS from 2024.X through 2024.5.X ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43442?
CVE-2024-43442 is considered a high severity vulnerability due to its potential for exploit through Cross-Site Scripting (XSS).
How do I fix CVE-2024-43442?
To mitigate CVE-2024-43442, update OTRS to a version that is not affected, specifically versions above 8.0.X and 2024.5.
Who is affected by CVE-2024-43442?
CVE-2024-43442 affects admins using OTRS versions from 7.0.0 to 7.0.50, all 8.0.X, and up to 2023.X, as well as versions between 2024.0 and 2024.5.
What kind of vulnerability is CVE-2024-43442?
CVE-2024-43442 is a Cross-Site Scripting (XSS) vulnerability caused by improper input neutralization in the OTRS System Configuration.
Can CVE-2024-43442 be exploited remotely?
Yes, CVE-2024-43442 can be exploited remotely by an attacker with admin privileges, allowing them to execute XSS attacks.