Логотип exploitDog
bind:CVE-2020-1767
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1767

Количество 4

Количество 4

ubuntu логотип

CVE-2020-1767

около 6 лет назад

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2020-1767

около 6 лет назад

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2020-1767

около 6 лет назад

Agent A is able to save a draft (i.e. for customer reply). Then Agent ...

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xqvr-25w4-fgw8

больше 3 лет назад

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-1767

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS3: 3.5
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-1767

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS3: 3.5
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-1767

Agent A is able to save a draft (i.e. for customer reply). Then Agent ...

CVSS3: 3.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-xqvr-25w4-fgw8

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу