znuny / Znuny

Znuny/Znuny LTS is a fork of the ((OTRS)) Community Edition, one of the most flexible web-based ticketing systems used for Customer Service, Help Desk, IT Service Management.
https://www.znuny.org
GNU General Public License v3.0
358 stars 85 forks source link

Does CVE-2021-36092 affect Znuny? #105

Closed carnil closed 3 years ago

carnil commented 3 years ago

In the recent update CVE-2021-36091, CVE-2021-21440 and CVE-2021-21443 were addressed.

There is https://otrs.com/release-notes/otrs-security-advisory-2021-15/ for the OTRS version, which is said to:

PRODUCT AFFECTED:

This issue affects ((OTRS)) Community Edition 6.0.x.

This issue affects OTRS 7.0.x, 8.0.x.

Does this issue affect as well Znuny, is more known about it?

hanneshal commented 3 years ago

Hi,

Yes. The chances are good, that we are affected by this. We did not managed to create a valid XSS in the ticket zoom view or other views which quote the E-Mail content.

The CVE is pretty vague about where and what and there are no information about this to the community from OTRS itself.

We modified the link detection logic for some special cases, but did not linked this to the CVE due to a missing example.

So without any more details about this or someone who can at least send a sample mail, we are not able to solve this here.

regards Johannes

carnil commented 3 years ago

@hanneshal thanks for the quick followup!