Bugzilla – Bug 1188738
VUL-1: CVE-2021-21442: otrs: injecting malicious JS code possible to certain fields
Last modified: 2021-07-27 10:42:23 UTC
CVE-2021-21442 In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-21442 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21442 http://www.cvedetails.com/cve/CVE-2021-21442/ https://otrs.com/release-notes/otrs-security-advisory-2021-12/
the version we ship in Leap is not affected, closing