Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3frj-7j4q-xc89

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

EPSS

Процентиль: 42%
0.00196
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

nvd
больше 14 лет назад

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

debian
больше 14 лет назад

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw ...

EPSS

Процентиль: 42%
0.00196
Низкий