Bugzilla – Bug 1188740
VUL-1: CVE-2021-36092: otrs: It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack
Last modified: 2021-07-27 11:15:11 UTC
CVE-2021-36092 It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-36092 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36092 http://www.cvedetails.com/cve/CVE-2021-36092/ https://otrs.com/release-notes/otrs-security-advisory-2021-15/
relevant for Leap