LigeroSmart Cross-Site Scripting Vulnerability in OTRS Index.pl SortBy Parameter
Vulnerability
A reflected cross-site scripting vulnerability has been identified in LigeroSmart versions prior to 6.1.26. The issue arises in the OTRS-based platform within the index.pl file, where the SortBy parameter is not properly validated or encoded. This flaw allows authenticated attackers to inject arbitrary JavaScript, which is then executed in the context of the user's browser. The vulnerability can be exploited remotely, but requires user interaction.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the victim's browser.
Reproduction
To reproduce this vulnerability, send a POST request to '/otrs/index.pl' with a crafted SortBy parameter that includes JavaScript code, such as an alert function. The injected script will be executed when the response is rendered in the browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
