CVE-2024-23790 — Improper Input Validation in Otrs
Severity
9.8CRITICALNVD
CNA3.5
EPSS
0.2%
top 59.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Description
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes.
This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
3OSV▶
CVE-2024-23790: Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes↗2024-01-29
GHSA▶
GHSA-m525-p4rf-7h93: Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes↗2024-01-29