Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.
2022-03-21T10:15:07.903
2024-11-21T06:38:43.050
Modified
CVSSv3.1: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | otrs | otrs | ≤ 7.0.32 | Yes |
Application | otrs | otrs | ≤ 8.0.19 | Yes |