Medium severity4.9NVD Advisory· Published Aug 26, 2024· Updated Apr 15, 2026
CVE-2024-43442
CVE-2024-43442
Description
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:
- OTRS from 7.0.X through 7.0.50
- OTRS 8.0.X
- OTRS 2023.X
- OTRS from 2024.X through 2024.5.X
- ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.