CVE-2018-7567Unrestricted File Upload in Otrs

Severity
7.2HIGHNVD
EPSS
2.2%
top 15.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4
Latest updateMay 14

Description

In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a command on the server during package installation. NOTE: the vendor disputes this issue stating "the behaviour is as designed and needed for different packages to be installed", "there is a security warning if the package i

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDotrs/otrs5.0.05.0.23+2
debiandebian/otrs2

🔴Vulnerability Details

2
GHSA
GHSA-pxj8-jw6j-jj8v: ** DISPUTED ** In the Admin Package Manager in Open Ticket Request System (OTRS) 52022-05-14
OSV
CVE-2018-7567: In the Admin Package Manager in Open Ticket Request System (OTRS) 52018-03-04

💥Exploits & PoCs

1
Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities2018-11-07

📋Vendor Advisories

1
Debian
CVE-2018-7567: otrs2 - In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through ...2018
CVE-2018-7567 — Unrestricted File Upload in Otrs | cvebase