PT-2020-15046 · Otrs+2 · Otrs+3
Martin Møller
·
Published
2020-03-27
·
Updated
2023-08-31
·
CVE-2020-1769
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS Community Edition versions 5.0.41 and prior
OTRS Community Edition versions 6.0.26 and prior
OTRS versions 7.0.15 and prior
Description
The issue is related to the use of autocomplete in the Username and Password fields on the login screens of both the agent and customer interfaces, which could be considered a security issue.
Recommendations
For OTRS Community Edition versions 5.0.41 and prior, consider disabling the autocomplete feature for the Username and Password fields as a temporary workaround.
For OTRS Community Edition versions 6.0.26 and prior, consider disabling the autocomplete feature for the Username and Password fields as a temporary workaround.
For OTRS versions 7.0.15 and prior, consider disabling the autocomplete feature for the Username and Password fields as a temporary workaround.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Otrs
Otrs Community Edition
Suse