An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X prior to 7.0.32, from 8.0.X prior to 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X up to and including 6.0.22.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
otrs survey |