First published: Mon Feb 08 2021(Updated: )
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS Survey | >=6.0.0<=6.0.20 | |
OTRS Survey | >=7.0.0<=7.0.19 |
Upgrade to Survey 7.0.20.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21434 is a vulnerability that allows a survey administrator to craft a survey in such a way that malicious code can be executed in the agent interface, affecting OTRS AG Survey 6.0.x version 6.0.20 and prior versions, and 7.0.x version 7.0.19 and prior versions.
The severity of CVE-2021-21434 is medium, with a severity value of 4.8.
CVE-2021-21434 affects OTRS AG Survey 6.0.x version 6.0.20 and prior versions, as well as 7.0.x version 7.0.19 and prior versions.
The vulnerability can be exploited by a survey administrator crafting a survey in such a way that malicious code can be executed in the agent interface.
Yes, a fix is available for CVE-2021-21434. Users should update to OTRS AG Survey version 6.0.21 or version 7.0.20 to mitigate the vulnerability.