It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-22726 It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
Fixes

Solution

Update to OTRS 7.0.29.


Workaround

No workaround given by the vendor.

History

Mon, 16 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
Title XSS attack in appointment edit popup screen XSS attack in appointment edit popup screen

cve-icon MITRE

Status: PUBLISHED

Assigner: OTRS

Published:

Updated: 2024-09-16T19:09:09.574Z

Reserved: 2021-07-01T00:00:00

Link: CVE-2021-36094

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-06T14:15:07.257

Modified: 2024-11-21T06:13:08.777

Link: CVE-2021-36094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.