PT-2005-5580 · Otrs · Open Ticket Request System

Moritz Naumann

·

Publicado

1970-01-01

·

Atualizado

2017-07-20

·

CVE-2005-3893

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 1.0.0 through 1.3.2 Open Ticket Request System (OTRS) versions 2.0.0 through 2.0.3
Description The issue allows remote attackers to execute arbitrary SQL commands and bypass authentication via the user parameter in the Login action. Additionally, remote authenticated users can exploit the vulnerability via the TicketID and ArticleID parameters of the AgentTicketPlain action. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Open Ticket Request System (OTRS) versions 1.0.0 through 1.3.2, update to a version outside of this range to mitigate the risk. For Open Ticket Request System (OTRS) versions 2.0.0 through 2.0.3, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the AgentTicketPlain action and the Login action until a patch is available. Avoid using the user, TicketID, and ArticleID parameters in the affected actions until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03039
BDU:2015-03040
BDU:2015-03041
CVE-2005-3893
DSA-973-1

Produtos afetados

Open Ticket Request System