Vulnerability Description
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Survey | >= 6.0.0, <= 6.0.20 |
Related Weaknesses (CWE)
References
- https://otrs.com/release-notes/otrs-security-advisory-2021-01/Vendor Advisory
- https://otrs.com/release-notes/otrs-security-advisory-2021-01/Vendor Advisory
FAQ
What is CVE-2021-21434?
CVE-2021-21434 is a vulnerability with a CVSS score of 3.5 (LOW). Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG...
How severe is CVE-2021-21434?
CVE-2021-21434 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21434?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Survey.