Authenticated remote code execution
CVE-2021-36100
6.4MEDIUM
What is CVE-2021-36100?
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Affected Version(s)
((OTRS)) Community Edition 6.0.1 < 6.0.x*
OTRS 8.0.x <= 8.0.19
OTRS 7.0.x <= 7.0.32
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Special thanks to Rayhan Ahmed and Maxime Brigaudeau for reporting these vulnerability.