Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93rq-vj87-fqr6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

EPSS

Процентиль: 42%
0.00196
Низкий

Связанные уязвимости

ubuntu
почти 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

nvd
почти 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

debian
почти 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request Sys ...

EPSS

Процентиль: 42%
0.00196
Низкий