Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93rq-vj87-fqr6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

EPSS

Процентиль: 73%
0.0157
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

nvd
больше 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

debian
больше 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request Sys ...

EPSS

Процентиль: 73%
0.0157
Низкий