OTRS是德国 (OTRS)公司的一个应用软件。一个服务管理软件。 OTRS AG OTRS 存在信息泄露漏洞,该漏洞源于Agents可以在没有所需权限的情况下在required中列出permissions。以下产品和版本受到影响:TRS AG ((OTRS)) 社区版 6.0.32 及之前的版本、OTRS AG OTRS 7.0.27 及之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.0.1 ~ 6.0.x* | - |
|
| OTRS AG | OTRS | 7.0.x ~ 7.0.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-36092 | 6.5 MEDIUM | XSS attack using special link in email |
| CVE-2021-21440 | 5.2 MEDIUM | Support Bundle includes S/Mime and PGP keys |
| CVE-2021-21442 | 4.5 MEDIUM | XSS vulnerability in Time Accounting |
| CVE-2021-21443 | 3.5 LOW | Unautorized listing of the customer user emails |
No comments yet