
إثبات مفهوم لاستغلال CVE-2022-32074 يوضح XSS مخزّن في osTicket عبر رفع ملف SVG خبيث في دليل قائمة الملفات.
1. Find the file listing directory, the root of the file download directoryм (file_uploads (this is an example)).
2. Load the following xssPayload.svg and open it
Example:
