Описание
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 6.0.5-1 |
| cosmic | not-affected | 6.0.5-1 |
| devel | DNE | |
| disco | not-affected | 6.0.5-1 |
| eoan | not-affected | 6.0.5-1 |
| esm-apps/bionic | not-affected | 6.0.5-1 |
| esm-apps/focal | not-affected | 6.0.5-1 |
| esm-apps/jammy | not-affected | 6.0.5-1 |
| esm-apps/xenial | needed |
Показывать по
EPSS
6.5 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4 ...
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
EPSS
6.5 Medium
CVSS2
8.8 High
CVSS3