OTRS是德国 (OTRS)公司的一个应用软件。一个服务管理软件。 OTRS AG OTRS 存在跨站脚本漏洞,攻击者可以创建一个包含特制链接的电子邮件来执行 XSS 攻击。以下产品和版本受到影响:OTRS AG ((OTRS)) 社区版 6.0.32 及之前的版本、OTRS AG OTRS 7.0.27 及之前的版本、OTRS AG OTRS 8.0.14 及之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.0.1 ~ 6.0.x* | - |
|
| OTRS AG | OTRS | 7.0.x ~ 7.0.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21440 | 5.2 MEDIUM | Support Bundle includes S/Mime and PGP keys |
| CVE-2021-21442 | 4.5 MEDIUM | XSS vulnerability in Time Accounting |
| CVE-2021-21443 | 3.5 LOW | Unautorized listing of the customer user emails |
| CVE-2021-36091 | 3.5 LOW | Unautorized access to the calendar appointments |
No comments yet