Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16587

Опубликовано: 28 сент. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8
CVSS3: 6.5

Описание

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

not-affected

6.0.11-1
devel

DNE

disco

not-affected

6.0.11-1
eoan

not-affected

6.0.11-1
esm-apps/bionic

needed

esm-apps/focal

not-affected

6.0.11-1
esm-apps/jammy

not-affected

6.0.11-1
esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]

Показывать по

5.8 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.

CVSS3: 6.5
debian
больше 7 лет назад

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before ...

CVSS3: 6.5
github
больше 3 лет назад

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.

suse-cvrf
больше 7 лет назад

Security update for otrs

5.8 Medium

CVSS2

6.5 Medium

CVSS3