{"id":"CVE-2023-1248","details":"Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.\n\n","modified":"2026-03-14T12:01:00.878117Z","published":"2023-03-20T09:15:11.877Z","references":[{"type":"ADVISORY","url":"https://otrs.com/release-notes/otrs-security-advisory-2023-01/"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"6.0.1"},{"last_affected":"6.0.34"}]},{"events":[{"introduced":"7.0.0"},{"fixed":"7.0.42"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1248.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}