Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3frj-7j4q-xc89

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

EPSS

Процентиль: 42%
0.00196
Низкий

Связанные уязвимости

ubuntu
почти 15 лет назад

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

nvd
почти 15 лет назад

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

debian
почти 15 лет назад

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw ...

EPSS

Процентиль: 42%
0.00196
Низкий