CVE-2023-5421

LOW

OTRS 6.0.0-6.0.34 and 7.0.0-7.0.46 - Authenticated Stored Cross-Site Scripting via CustomerID Field Manipulation

Title source: llm
STIX 2.1

Description

An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs immediatly after the data is saved.The issue onlyoccurs if the configuration for AdminCustomerUser::UseAutoComplete was changed before. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

References (1)

Core 1

Scores

CVSS v3 3.5
EPSS 0.0037
EPSS Percentile 29.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-79
Status published
Products (2)
otrs/otrs 6.0.0 - 6.0.34
otrs/otrs 7.0.0 - 7.0.47
Published Oct 16, 2023
Tracked Since Feb 18, 2026