Description
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to OTRS 7.0.33 and OTRS 8.0.20.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15613 | Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions. |
References
History
No history.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-17T02:01:40.604Z
Reserved: 2022-02-02T00:00:00.000Z
Link: CVE-2022-0475
No data.
Status : Modified
Published: 2022-03-21T10:15:07.903
Modified: 2024-11-21T06:38:43.050
Link: CVE-2022-0475
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD