CVE-2024-43443: Stored XSS in process management
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects:
OTRS from 7.0.X through 7.0.50 OTRS 8.0.X OTRS 2023.X OTRS from 2024.X through 2024.5.X ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43443?
CVE-2024-43443 is classified as a high severity vulnerability due to its exploitation potential leading to Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-43443?
To fix CVE-2024-43443, update your OTRS or OTRS Community Edition to the latest version that addresses this vulnerability.
What versions are affected by CVE-2024-43443?
CVE-2024-43443 affects OTRS versions from 7.0.0 to 7.0.51, versions starting from 8.0.X, and versions from 2023.X up to 2024.6.
What type of vulnerability is CVE-2024-43443?
CVE-2024-43443 is a Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input.
Who is at risk from CVE-2024-43443?
Administrators using affected versions of OTRS or OTRS Community Edition are at risk due to the potential for XSS attacks targeting other admins.