An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.
2018-08-04T01:29:03.997
2024-11-21T03:49:22.327
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | otrs | open_ticket_request_system | ≤ 4.0.30 | Yes |
Application | otrs | open_ticket_request_system | ≤ 5.0.28 | Yes |
Application | otrs | open_ticket_request_system | ≤ 6.0.9 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |