Tickets can be moved without permissions
CVE-2023-38058

4.1MEDIUM

Key Information:

Vendor

Otrs Ag

Status
Vendor
CVE Published:
24 July 2023

What is CVE-2023-38058?

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

Affected Version(s)

OTRS 8.0.x

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.