7.2
CVSSv3

CVE-2023-38056

Published: 24/07/2023 Updated: 01/08/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X prior to 7.0.45, from 8.0.X prior to 8.0.35; ((OTRS)) Community Edition: from 6.0.1 up to and including 6.0.34.

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs