Name | CVE-2021-36094 |
Description | It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
OTRS, it's unclear to which extent Znuny might be affected since OTRS AG doesn't release
actionable information, also see https://github.com/znuny/Znuny/issues/128 and #993846