Description
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
Published: 2021-09-06
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update to OTRS 7.0.29.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-22726 It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
History

Mon, 16 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
Title XSS attack in appointment edit popup screen XSS attack in appointment edit popup screen

cve-icon MITRE

Status: PUBLISHED

Assigner: OTRS

Published:

Updated: 2024-09-16T19:09:09.574Z

Reserved: 2021-07-01T00:00:00.000Z

Link: CVE-2021-36094

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-06T14:15:07.257

Modified: 2024-11-21T06:13:08.777

Link: CVE-2021-36094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses