External pictures can be loaded even if not allowed by configuration
CVE-2023-38059

5.3MEDIUM

Key Information:

Vendor

Otrs Ag

Vendor
CVE Published:
16 October 2023

What is CVE-2023-38059?

The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

Affected Version(s)

((OTRS)) Community Edition 6.0.x <= 6.0.34

OTRS 7.0.x

OTRS 7.0.x < 7.0.47

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Special thanks to Tim PĂĽttmanns for reporting these vulnerability.
.