CVE-2021-21442
26.07.2021, 05:15
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.
Vendor | Product | Version |
---|---|---|
otrs | time_accounting | 7.0.0 ≤ 𝑥 < 7.0.20 |
𝑥
= Vulnerable software versions