SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21442

In the project create screen it's possible to inject malicious JS code to the certain fields.

MEDIUM 5.4EPSS 0.60%

Does this matter?

Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.

Description

In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.60% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
otrs/time accounting
Source
security@otrs.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.