Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Otrs Subscribe
Filtered by product Time Accounting
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-21442 1 Otrs 1 Time Accounting 2021-08-04 4.3 MEDIUM 5.4 MEDIUM
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.