CVE-2023-38057 is an improper input validation vulnerability in the OTRS Survey module, affecting versions 7.0.X prior to 7.0.32, 8.0.X prior to 8.0.13, and ((OTRS)) Community Edition Survey module 6.0.X through 6.0.22. An attacker with a valid, unanswered survey link can inject JavaScript into free text answers, leading to a cross-site scripting (XSS) attack when an authenticated agent views the replies. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low confidentiality and integrity impacts. Its EPSS score is low, suggesting a low probability of exploitation. Currently, there is no evidence of active exploitation, and no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been observed for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.0.22CPE matchmatch criteria | cpe:2.3:a:otrs:survey:*:*:*:*:community:*:*:* | ||
>= 7.0.0, < 7.0.32CPE matchmatch criteria | cpe:2.3:a:otrs:survey:*:*:*:*:-:*:*:* | ||
>= 8.0.0, < 8.0.13CPE matchmatch criteria | cpe:2.3:a:otrs:survey:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.