Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-3551

Опубликовано: 21 фев. 2020
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.20 (исключая)
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.1.16 (исключая)
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.7 (исключая)
cpe:2.3:a:otrs:otrs_itsm:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.8 (исключая)
cpe:2.3:a:otrs:otrs_itsm:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.1.9 (исключая)
cpe:2.3:a:otrs:otrs_itsm:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.5 (исключая)

EPSS

Процентиль: 64%
0.00479
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

CVSS3: 6.5
debian
почти 6 лет назад

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS ...

CVSS3: 6.5
github
почти 4 года назад

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

EPSS

Процентиль: 64%
0.00479
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200