Incorrect Privilege Assignment in Inline Editing Can Lead to Privilege Escalation
CVE-2024-23794
What is CVE-2024-23794?
An incorrect privilege assignment vulnerability exists in the inline editing functionality of OTRS. This flaw allows agents with only read-only permissions to elevate their access, potentially gaining full control over tickets. The vulnerability is triggered under rare circumstances when the system configuration contains the 'RequiredLock' setting of 'AgentFrontend::Ticket::InlineEditing::Property###Watch' enabled by an administrator. This issue compromises the integrity of user permissions and is applicable to specific OTRS versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OTRS 8.0.x
OTRS 2023.x
OTRS 2024.x <= 2024.4.x
References
CVSS V3.1
Timeline
Vulnerability published
