Improper Privilege Management in OTRS Affects Multiple Versions
CVE-2024-43446
3.5LOW
What is CVE-2024-43446?
An improper privilege management flaw in the OTRS Generic Interface module permits users with read-only permissions to alter ticket statuses. This significant oversight can jeopardize the integrity of ticket management, potentially allowing unauthorized users to escalate their permissions and manipulate critical ticket workflows. All users of OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X, as well as ((OTRS)) Community Edition 6.0.x, are advised to assess their systems and implement security measures urgently.
Affected Version(s)
((OTRS)) Community Edition 6.0.x <= 6.0.34
OTRS 7.0.x
OTRS 7.0.x