5.8
CVSSv2

CVE-2018-16587

Published: 28/09/2018 Updated: 21/11/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

In Open Ticket Request System (OTRS) 4.0.x prior to 4.0.32, 5.0.x prior to 5.0.30, and 6.0.x prior to 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

otrs open ticket request system

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Three vulnerabilities were discovered in the Open Ticket Request System which could result in privilege escalation or denial of service For the stable distribution (stretch), these problems have been fixed in version 5016-1+deb9u6 We recommend that you upgrade your otrs2 packages For the detailed security status of otrs2 please refer to its se ...