Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38056


Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.


Published

2023-07-24T09:15:09.403

Last Modified

2024-11-21T08:12:45.833

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application otrs otrs ≤ 6.0.34 Yes
Application otrs otrs < 7.0.45 Yes
Application otrs otrs < 8.0.35 Yes

References