Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q58q-5fj7-r8px

Опубликовано: 24 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

EPSS

Процентиль: 36%
0.00153
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-269
CWE-863

Связанные уязвимости

CVSS3: 4.1
ubuntu
больше 2 лет назад

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

CVSS3: 4.1
nvd
больше 2 лет назад

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

EPSS

Процентиль: 36%
0.00153
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-269
CWE-863