CVE-2023-38059Sensitive Information Exposure in AG Otrs

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5otrs_ag/community_edition6.0.x6.0.34
NVDotrs/otrs7.0.07.0.47+2
CVEListV5otrs_ag/otrs7.0.x7.0.47+1

🔴Vulnerability Details

3
CVEList
External pictures can be loaded even if not allowed by configuration2023-10-16
OSV
CVE-2023-38059: The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload2023-10-16
GHSA
GHSA-6gr4-x7gv-xwjp: The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload2023-10-16
CVE-2023-38059 — Sensitive Information Exposure | cvebase