← Back to CVE List
Vulnerability Intelligence Report
XSS in the ticket overview screens

CVE-2021-21441

There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:1.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-79 ↗CWE-79 Cross-site Scripting (XSS)

Affected Products & Versions

Vendor Product Affected Versions
OTRS AG ((OTRS)) Community Edition 6.0.1 < 6.0.x* (affected)
OTRS AG OTRS 7.0.x <= 7.0.26 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.216%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityOTRS AG · Vendor · Germany
Reserved2020-12-29T00:00:00
Published2021-06-16T09:50:11
Patch Date2021-06-16
Last Updated2024-09-16T16:23:02

LINK COPIED TO CLIPBOARD