CVE-2022-0475 LOW

CVE-2022-0475: Possible XSS attack via translation

Vendor Otrs Ag
Product OTRS
Weakness CWE-79 · XSS
Published March 21, 2022
Last update September 17, 2024

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

Key dates

02Disclosure timeline

March 21, 2022 CVE published
September 17, 2024 Record updated