OTRS是德国 (OTRS)公司的一个应用软件。一个服务管理软件。 OTRS 7.0.37之前的7.0.x版本、8.0.25之前的OTRS 8.0.x版本存在安全漏洞,该漏洞源于以管理员用户身份登录OTRS的攻击者可能会操纵客户URL字段来存储JavaScript代码,以便以后任何其他代理在点击客户URL链接时运行存储的JavaScript在OTRS的上下文中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | OTRS | 7.0.x ~ 7.0.36 | - |
|
| OTRS AG | ((OTRS)) Community Edition | 6.0.1 ~ 6.0.x* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39051 | 6.8 MEDIUM | Perl Code execution in Template Toolkit |
| CVE-2022-39049 | 3.5 LOW | Possible XSS in Admin Interface |
No comments yet