CVE-2013-3551Sensitive Information Exposure in Otrs

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 34.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 21
Latest updateMay 5

Description

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDotrs/otrs_itsm3.0.03.0.8+2
NVDotrs/otrs3.0.03.0.20+2

🔴Vulnerability Details

3
GHSA
GHSA-rw85-3j9f-967p: Kernel/Modules/AgentTicketPhone2022-05-05
OSV
CVE-2013-3551: Kernel/Modules/AgentTicketPhone2020-02-21
CVEList
CVE-2013-3551: Kernel/Modules/AgentTicketPhone2020-02-21

📋Vendor Advisories

1
Debian
CVE-2013-3551: otrs2 - Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x be...2013
CVE-2013-3551 — Sensitive Information Exposure in Otrs | cvebase