OTRS是德国 (OTRS)公司的一个应用软件。一个服务管理软件。 OTRS AG ((OTRS)) Community Edition存在信息泄露漏洞,该漏洞源于生成的支持包包含私有的S MIME和PGP密钥,如果包含的文件夹没有被隐藏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.0.1 ~ 6.0.x* | - |
|
| OTRS AG | OTRS | 7.0.x ~ 7.0.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-36092 | 6.5 MEDIUM | XSS attack using special link in email |
| CVE-2021-21442 | 4.5 MEDIUM | XSS vulnerability in Time Accounting |
| CVE-2021-21443 | 3.5 LOW | Unautorized listing of the customer user emails |
| CVE-2021-36091 | 3.5 LOW | Unautorized access to the calendar appointments |
No comments yet