Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-38057

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.5%
CVSS Severity
CVSS v3 Score 4.1
Products affected by CVE-2023-38057
  • Otrs » Survey » Version: Any
    cpe:2.3:a:otrs:survey:*


Contact Us

Shodan ® - All rights reserved