CVE-2021-21442: XSS vulnerability in Time Accounting
Published Jul 26, 2021
·Updated
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.
Affected Software
1 affected component
OTRS Time Accounting>=7.0.0<7.0.20
Remediation
Information
Update to OTRS TimeAccounting 7.0.20.
Event History
Jul 26, 2021
CVE Published
via MITRE·04:25 AM
Data Sourced
via MITRE·04:25 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-21442.
2
What is the severity of CVE-2021-21442?
The severity of CVE-2021-21442 is medium with a severity value of 5.4.
3
How does CVE-2021-21442 affect OTRS AG Time Accounting?
CVE-2021-21442 affects OTRS AG Time Accounting versions prior to 7.0.19.
4
How can the code injection in the project create screen be exploited?
The code injection in the project create screen can be exploited to inject malicious JavaScript code into certain fields, which may be executed in the Reporting screen.
5
How can I fix CVE-2021-21442?
To fix CVE-2021-21442, it is recommended to upgrade OTRS AG Time Accounting to version 7.0.19 or later.