Vulnerabilities (CVE)

Filtered by vendor Otrs
Filtered by product Time Accounting
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-21442 1 Otrs 1 Time Accounting 2024-11-21 4.3 MEDIUM 4.5 MEDIUM
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.