VYPR
High severity7.2NVD Advisory· Published Jul 24, 2023· Updated Jun 17, 2026

CVE-2023-38056

CVE-2023-38056

Description

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • OTRS/Otrs4 versions
    cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*+ 3 more
    • cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*range: >=7.0.0,<7.0.45
    • cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*range: >=6.0.1,<=6.0.34
    • (no CPE)range: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35
    • (no CPE)range: 7.0.x
  • OTRS/((OTRS)) Community Editionllm-fuzzy2 versions
    from 6.0.1 through 6.0.34+ 1 more
    • (no CPE)range: from 6.0.1 through 6.0.34
    • (no CPE)range: 6.0.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.