Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxq2-55c8-f947

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.

Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.

EPSS

Процентиль: 38%
0.0016
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.

nvd
почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.

debian
почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly ...

EPSS

Процентиль: 38%
0.0016
Низкий

Дефекты

CWE-20