
Exploit de prueba de concepto para CVE-2022-32074 que demuestra XSS almacenado en osTicket mediante la carga de un archivo SVG malicioso en el directorio de listado de archivos.
1. Find the file listing directory, the root of the file download directoryм (file_uploads (this is an example)).
2. Load the following xssPayload.svg and open it
Ejemplo:
