Insufficient access control
CVE-2024-23792

6.5MEDIUM

Key Information:

Vendor

OTRS AG

Status
Vendor
CVE Published:
29 January 2024

What is CVE-2024-23792?

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment.

This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

Affected Version(s)

OTRS 7.0.x <= 7.0.48

OTRS 8.0.x <= 8.0.37

OTRS 2023.x <= 2023.1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Special thanks to Matthias PĂĽschel for reporting these vulnerability.
.