CVE-2023-38057 MEDIUM

CVE-2023-38057: XSS stored in survey answers

Vendor Otrs Ag
Product OTRS
Weakness CWE-20 · Input validation
Published July 24, 2023
Last update October 17, 2024

CVSS base score

4.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

Key dates

02Disclosure timeline

July 24, 2023 CVE published
October 17, 2024 Record updated