Description
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.
Published: 2021-02-08
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to Survey 7.0.20.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8708 Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: OTRS

Published:

Updated: 2024-09-17T03:54:55.677Z

Reserved: 2020-12-29T00:00:00.000Z

Link: CVE-2021-21434

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-08T11:15:14.080

Modified: 2024-11-21T05:48:21.277

Link: CVE-2021-21434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses