
Proof-of-concept exploit per CVE-2022-32074 che dimostra una XSS persistente in osTicket tramite il caricamento di un file SVG dannoso nella directory di elenco dei file.
1. Find the file listing directory, the root of the file download directoryм (file_uploads (this is an example)).
2. Load the following xssPayload.svg and open it
Esempio:
