CVE-2021-36094: XSS attack in appointment edit popup screen
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36094.
What is the severity of CVE-2021-36094?
The severity of CVE-2021-36094 is medium with a severity value of 5.4.
Which software versions are affected by CVE-2021-36094?
OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions, and OTRS AG OTRS 7.0.x version 7.0.28 and prior versions are affected.
How can CVE-2021-36094 be exploited?
CVE-2021-36094 can be exploited by crafting a request for the appointment edit screen, which could lead to an XSS attack.
Is there a fix available for CVE-2021-36094?
Yes, a fix for CVE-2021-36094 is available. Please refer to the following link for more information: https://otrs.com/release-notes/otrs-security-advisory-2021-17/