6.5
CVSSv2

CVE-2018-14593

Published: 04/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Open Ticket Request System (OTRS) 6.0.x up to and including 6.0.9, 5.0.x up to and including 5.0.28, and 4.0.x up to and including 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

otrs open ticket request system

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Three vulnerabilities were discovered in the Open Ticket Request System which could result in privilege escalation or denial of service For the stable distribution (stretch), these problems have been fixed in version 5016-1+deb9u6 We recommend that you upgrade your otrs2 packages For the detailed security status of otrs2 please refer to its se ...