#VU51872 Cross-site scripting in OTRS - CVE-2021-21434
Published: February 8, 2021 / Updated: April 1, 2021
OTRS
otrs.org
Description
The vulnerability allows a remote privileged user to read and manipulate data.
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.