CVE-2020-1765
published 2020-01-10CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.50%
71.6th percentile
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | otrs2 | < otrs2 6.0.25-1 (bullseye) | otrs2 6.0.25-1 (bullseye) |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| otrs | otrs | 5.0.0 – 5.0.39 | — |
| otrs | otrs | 6.0.0 – 6.0.24 | — |
| otrs | otrs | 7.0.0 – 7.0.13 | — |
| otrs_ag | community_edition | — | — |
| otrs_ag | community_edition | — | — |
| otrs_ag | otrs | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rfv4-xfv7-5r3p: An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicket
ghsa_unreviewed·2022-05-24
CVE-2020-1765 [MEDIUM] CWE-472 GHSA-rfv4-xfv7-5r3p: An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicket
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
OSV
CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicket
osv·2020-01-10·CVSS 5.3
CVE-2020-1765 [MEDIUM] CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicket
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Debian
CVE-2020-1765: otrs2 - An improper control of parameters allows the spoofing of the from fields of the ...
vendor_debian·2020·CVSS 3.5
CVE-2020-1765 [LOW] CVE-2020-1765: otrs2 - An improper control of parameters allows the spoofing of the from fields of the ...
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Scope: local
bullseye: resolved (fixed in 6.0.25-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://otrs.com/release-notes/otrs-security-advisory-2020-01/http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://otrs.com/release-notes/otrs-security-advisory-2020-01/
2020-01-10
Published