Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13458

Опубликовано: 21 авг. 2019
Источник: nvd
CVSS3: 2.7
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
Версия от 5.0.0 (включая) до 5.0.36 (включая)
cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
Версия от 6.0.0 (включая) до 6.0.19 (включая)
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.8 (включая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.00437
Низкий

2.7 Low

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

CVSS3: 6.5
debian
почти 6 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...

CVSS3: 6.5
github
около 3 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

suse-cvrf
почти 5 лет назад

Recommended update for otrs

suse-cvrf
больше 5 лет назад

Recommended update for otrs

EPSS

Процентиль: 62%
0.00437
Низкий

2.7 Low

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

NVD-CWE-noinfo