Specially crafted string in OTRS system configuration can allow the execution of any system command.
2022-03-21T10:15:07.777
2024-11-21T06:13:09.263
Modified
CVSSv3.1: 6.4 (MEDIUM)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | otrs | otrs | < 7.0.28 | Yes |
Application | otrs | otrs | < 7.0.33 | Yes |
Application | otrs | otrs | < 8.0.21 | Yes |
Application | otrs | otrs_itsm | < 7.0.19 | Yes |
Application | otrs | otrs_itsm | < 8.0.28 | Yes |
Application | otrs | otrs_storm | < 8.0.12 | Yes |