cbcvebase.
CVE-2020-1765
published 2020-01-10

CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianotrs2< otrs2 6.0.25-1 (bullseye)otrs2 6.0.25-1 (bullseye)
opensusebackports_sle
opensuseleap
opensuseleap
otrsotrs5.0.0 – 5.0.39
otrsotrs6.0.0 – 6.0.24
otrsotrs7.0.0 – 7.0.13
otrs_agcommunity_edition
otrs_agcommunity_edition
otrs_agotrs

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM