PT-2021-21112 · Otrs Ag+1 · Otrs+2
Published
2021-07-26
·
Updated
2024-08-06
·
CVE-2021-36092
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OTRS AG (OTRS) Community Edition versions 6.0.1 and later
OTRS AG OTRS versions prior to 7.0.28
OTRS AG OTRS versions prior to 8.0.15
Description:
It is possible to create an email that contains a specially crafted link, which can be used to perform a cross-site scripting (XSS) attack.
Recommendations:
For OTRS AG (OTRS) Community Edition version 6.0.1 and later, update to a version that includes a fix for this issue.
For OTRS AG OTRS version 7.0.x, update to version 7.0.28 or later.
For OTRS AG OTRS version 8.0.x, update to version 8.0.15 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Otrs
Otrs Community Edition