
Эксплойт proof-of-concept для CVE-2022-32074, демонстрирующий хранимую XSS-уязвимость в osTicket через загрузку вредоносного SVG-файла в каталоге листинга файлов.
1. Find the file listing directory, the root of the file download directoryм (file_uploads (this is an example)).
2. Load the following xssPayload.svg and open it
Example:
