CVE-2022-39049
EUVD-2022-4159505.09.2022, 07:15
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| otrs | otrs | 6.0.0 ≤ 𝑥 ≤ 6.0.32 |
| otrs | otrs | 7.0.0 ≤ 𝑥 < 7.0.37 |
| otrs | otrs | 8.0.0 ≤ 𝑥 < 8.0.25 |
𝑥
= Vulnerable software versions
Ubuntu Releases