CVE-2023-38057
Published Jul 24, 2023An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text a…
Vendor/product archive
2 CVEs tagged to otrs / survey — 0 Critical, 0 High, 1 Medium, 1 Low, 0 Unrated.
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text a…
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This i…