Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-14593

Опубликовано: 04 авг. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:otrs:open_ticket_request_system:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.30 (включая)
cpe:2.3:a:otrs:open_ticket_request_system:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.28 (включая)
cpe:2.3:a:otrs:open_ticket_request_system:*:*:*:*:*:*:*:*
Версия от 6.0.0 (включая) до 6.0.9 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00681
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

CVSS3: 8.8
debian
больше 7 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x thr ...

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

suse-cvrf
около 7 лет назад

Security update for otrs

EPSS

Процентиль: 71%
0.00681
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo