Information exposure of template content due to missing check of permissions
CVE-2022-3501

3.5LOW

What is CVE-2022-3501?

Article template contents with sensitive data could be accessed from agents without permissions.

Affected Version(s)

OTRS 8.0.x <= 8.0.25

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.