First published: Mon Aug 26 2024(Updated: )
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=7.0.0<7.0.51 | |
OTRS | >=8.0.X | |
OTRS | >=2023.X | |
OTRS | >=2024.0<2024.6 | |
>=6.0.X |
Update to OTRS 2024.6.x or OTRS 7.0.51
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43443 is classified as a high severity vulnerability due to its exploitation potential leading to Cross-Site Scripting (XSS) attacks.
To fix CVE-2024-43443, update your OTRS or OTRS Community Edition to the latest version that addresses this vulnerability.
CVE-2024-43443 affects OTRS versions from 7.0.0 to 7.0.51, versions starting from 8.0.X, and versions from 2023.X up to 2024.6.
CVE-2024-43443 is a Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input.
Administrators using affected versions of OTRS or OTRS Community Edition are at risk due to the potential for XSS attacks targeting other admins.