Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4h85-vpxq-834q

Опубликовано: 29 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment.

This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment.

This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

EPSS

Процентиль: 28%
0.00102
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

CVSS3: 5.3
nvd
около 2 лет назад

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость системы обработки заявок OTRS, связанная с недостатками процедуры аутентификации, позволяющая нарушителю добавить дополнительные файлы к комментарию произвольного пользователя

EPSS

Процентиль: 28%
0.00102
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287