Unrated severityNVD Advisory· Published Jan 29, 2024· Updated Nov 12, 2024
Insufficient access control
CVE-2024-23792
Description
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment.
This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- otrs.com/release-notes/otrs-security-advisory-2024-03/mitrevendor-advisory
News mentions
0No linked articles in our index yet.