Vulnerabilities
Vulnerable Software
Otrs:  >> Otrs  >> 2023.0.0  Security Vulnerabilities
Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
CVSS Score
4.9
EPSS Score
0.005
Published
2024-01-29
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
CVSS Score
5.3
EPSS Score
0.003
Published
2024-01-29
The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.017
Published
2011-07-19


Contact Us

Shodan ® - All rights reserved