OTRS AG Survey是德国OTRS公司的一款基于Perl语言的客户调查用具。该工具用于用于在车票关闭后向客户发送电子邮件。 OTRS AG Survey 中存在跨站脚本漏洞,该漏洞源于允许恶意代码可以在代理接口中执行。以下产品及版本受到影响:6.0。x、6.0.20和以前的版本、7.0。x版本、7.0.19和以前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21435 | 5.7 MEDIUM | Information exposure in PDF export |
| CVE-2020-1779 | 4.3 MEDIUM | Dynamic templates reveal sensitive data when OTRS tags are used |
| CVE-2021-21436 | 3.5 LOW | Agent is able to link customer's Config Items without permission |
No comments yet