another user can add attachments as well impersonating the orginal user. The attack requires a
logged-in other user to know the UUID. While the legitimate user
completes the comment, the malicious user can add more files to the
comment.
This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to OTRS Patch 2024.1.1 Update to OTRS 7.0.49 (Long Term Support Users)
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21245 | When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1. |
Tue, 12 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-11-12T21:47:04.433Z
Reserved: 2024-01-22T10:32:00.704Z
Link: CVE-2024-23792
Updated: 2024-08-01T23:13:07.447Z
Status : Modified
Published: 2024-01-29T10:15:08.683
Modified: 2024-11-21T08:58:25.700
Link: CVE-2024-23792
No data.
OpenCVE Enrichment
No data.
EUVD