PT-2021-14507 · Otrs Ag+1 · Otrs+1
László Gyaraki
·
Published
2021-02-08
·
Updated
2024-08-06
·
CVE-2021-21435
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS AG OTRS versions 7.0.x through 7.0.23
OTRS AG OTRS versions 8.0.x through 8.0.10
Description
The issue concerns the exposure of Article Bcc fields and agent personal information when a customer prints a ticket in PDF format via an external interface.
Recommendations
For versions 7.0.x through 7.0.23, update to a version newer than 7.0.23 to resolve the issue.
For versions 8.0.x through 8.0.10, update to a version newer than 8.0.10 to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Otrs