First published: Mon Aug 26 2024(Updated: )
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=7.0.0<=7.0.50 | |
OTRS | <=8.0.X | |
OTRS | <=2023.X | |
OTRS | >=2024.0<2024.5 | |
OTRS | <=6.0.x |
Update to OTRS 2024.6.x or OTRS 7.0.51
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43442 is considered a high severity vulnerability due to its potential for exploit through Cross-Site Scripting (XSS).
To mitigate CVE-2024-43442, update OTRS to a version that is not affected, specifically versions above 8.0.X and 2024.5.
CVE-2024-43442 affects admins using OTRS versions from 7.0.0 to 7.0.50, all 8.0.X, and up to 2023.X, as well as versions between 2024.0 and 2024.5.
CVE-2024-43442 is a Cross-Site Scripting (XSS) vulnerability caused by improper input neutralization in the OTRS System Configuration.
Yes, CVE-2024-43442 can be exploited remotely by an attacker with admin privileges, allowing them to execute XSS attacks.