Back

MEDIUM

Possible XSS attack via translation

Published Mar 21, 2022

Description

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

Affected products

Remediation

Vendor solution

Update to OTRS 7.0.33 and OTRS 8.0.20.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OTRS
Published Mar 21, 2022
Updated Sep 17, 2024
Reserved Feb 2, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner OTRS
Published Mar 21, 2022
Updated Sep 17, 2024
Exploited since n/a
EUVD-2022-15613