Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-21435— Information exposure in PDF export

CVSS 5.7 · Medium EPSS 0.29% · P52
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-21435

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Information exposure in PDF export
Source: NVD (National Vulnerability Database)
Vulnerability Description
Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
OTRS ITSM 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OTRS ITSM是德国OTRS公司的一套IT服务管理组织的基础解决方案。该方案以ITIL最佳实践为基础,提供请求和故障管理、问题管理、变更管理和发布管理的管理工具。 OTRS AG OTRS 中存在信息泄露漏洞,该漏洞源于当客户通过外部接口打印票据(PDF)时,将显示文章密件字段和代理人个人信息。以下产品及型号受到影响:OTRS AG OTRS 7.0.x、7.0.23和以前的版本、8.0。x版本、8.0.10和以前的版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
OTRS AGOTRS 7.0.x ~ 7.0.23 -

II. Public POCs for CVE-2021-21435

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-21435

登录查看更多情报信息。

Same Patch Batch · OTRS AG · 2021-02-08 · 4 CVEs total

CVE-2020-17794.3 MEDIUMDynamic templates reveal sensitive data when OTRS tags are used
CVE-2021-214343.5 LOWXSS in Survey Module
CVE-2021-214363.5 LOWAgent is able to link customer's Config Items without permission

IV. Related Vulnerabilities

V. Comments for CVE-2021-21435

No comments yet


Leave a comment