CVE-2023-38057

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:survey:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:survey:*:*:*:*:-:*:*:*
cpe:2.3:a:otrs:survey:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2023-07-24 09:15

Updated : 2023-08-04 18:48


NVD link : CVE-2023-38057

Mitre link : CVE-2023-38057

CVE.ORG link : CVE-2023-38057


JSON object : View

Products Affected

otrs

  • survey
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-20

Improper Input Validation