OTRS是德国 (OTRS)公司的一个应用软件。一个服务管理软件。 OTRS AG ((OTRS)) Community Edition存在信息泄露漏洞,该漏洞源于代理可以在批量操作屏幕中列出客户用户电子邮件,而不需要权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.0.1 ~ 6.0.x* | - |
|
| OTRS AG | OTRS | 7.0.x ~ 7.0.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-36092 | 6.5 MEDIUM | XSS attack using special link in email |
| CVE-2021-21440 | 5.2 MEDIUM | Support Bundle includes S/Mime and PGP keys |
| CVE-2021-21442 | 4.5 MEDIUM | XSS vulnerability in Time Accounting |
| CVE-2021-36091 | 3.5 LOW | Unautorized access to the calendar appointments |
No comments yet