Description
It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to OTRS 8.0.15 or OTRS 7.0.28.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-22724 | It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions. |
References
History
No history.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-17T03:02:46.230Z
Reserved: 2021-07-01T00:00:00.000Z
Link: CVE-2021-36092
No data.
Status : Modified
Published: 2021-07-26T05:15:07.640
Modified: 2024-11-21T06:13:08.520
Link: CVE-2021-36092
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD