First published: Mon Jul 26 2021(Updated: )
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Time Accounting | >=7.0.0<7.0.20 |
Update to OTRS TimeAccounting 7.0.20.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21442.
The severity of CVE-2021-21442 is medium with a severity value of 5.4.
CVE-2021-21442 affects OTRS AG Time Accounting versions prior to 7.0.19.
The code injection in the project create screen can be exploited to inject malicious JavaScript code into certain fields, which may be executed in the Reporting screen.
To fix CVE-2021-21442, it is recommended to upgrade OTRS AG Time Accounting to version 7.0.19 or later.