Possible XSS in Ticket Actions
CVE-2023-1248

6.1MEDIUM

Key Information:

Vendor

Otrs Ag

Vendor
CVE Published:
20 March 2023

What is CVE-2023-1248?

Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

Affected Version(s)

((OTRS)) Community Edition 6.0.1 <= 6.0.34

OTRS 7.0.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.