In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions before 7.0.19.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
otrs time accounting |