
CVE-2022-32074の概念実証エクスプロイト。ファイル一覧ディレクトリへの悪意のあるSVGファイルのアップロードを介して、osTicketに保存型XSSが発生することを実証します。
1. Find the file listing directory, the root of the file download directoryм (file_uploads (this is an example)).
2. Load the following xssPayload.svg and open it
例:
