CVE-2021-36092Cross-site Scripting in AG Community Edition

Severity
6.1MEDIUMNVD
CNA6.5
EPSS
0.4%
top 41.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 24

Description

It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

CVEListV5otrs_ag/community_edition6.0.16.0.x*
NVDotrs/otrs7.0.07.0.28+2
CVEListV5otrs_ag/otrs7.0.x7.0.27+1

🔴Vulnerability Details

3
GHSA
GHSA-r4rg-fqhp-766m: It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack2022-05-24
OSV
CVE-2021-36092: It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack2021-07-26
CVEList
XSS attack using special link in email2021-07-26
CVE-2021-36092 — Cross-site Scripting | cvebase