CVE-2018-19143Forced Browsing in Open Ticket Request System

CWE-425Forced Browsing4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 68.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 13

Description

Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDotrs/open_ticket_request_system4.0.04.0.33+2
debiandebian/otrs2< otrs2 6.0.13-1 (bullseye)

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xm8f-ghm9-8g26: Open Ticket Request System (OTRS) 42022-05-13
OSV
CVE-2018-19143: Open Ticket Request System (OTRS) 42018-11-11

📋Vendor Advisories

1
Debian
CVE-2018-19143: otrs2 - Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and ...2018