NA

CVE-2023-38060

Published: 24/07/2023 Updated: 31/08/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated malicious user to to perform an host header injection for the ContentType header of the attachment.  This issue affects OTRS: from 7.0.X prior to 7.0.45, from 8.0.X prior to 8.0.35; ((OTRS)) Community Edition: from 6.0.1 up to and including 6.0.34.

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs