
Proof-of-concept Exploit für CVE-2022-32074, der gespeichertes XSS in osTicket über den Upload einer bösartigen SVG-Datei im Dateiliste-Verzeichnis demonstriert.
1. Find the file listing directory, the root of the file download directoryм (file_uploads (this is an example)).
2. Load the following xssPayload.svg and open it
Beispiel:
