Improper Privilege Management in OTRS Affects Multiple Versions
CVE-2024-43446

3.5LOW

Key Information:

Vendor

Otrs Ag

Vendor
CVE Published:
27 January 2025

What is CVE-2024-43446?

An improper privilege management flaw in the OTRS Generic Interface module permits users with read-only permissions to alter ticket statuses. This significant oversight can jeopardize the integrity of ticket management, potentially allowing unauthorized users to escalate their permissions and manipulate critical ticket workflows. All users of OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X, as well as ((OTRS)) Community Edition 6.0.x, are advised to assess their systems and implement security measures urgently.

Affected Version(s)

((OTRS)) Community Edition 6.0.x <= 6.0.34

OTRS 7.0.x

OTRS 7.0.x

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.