PT-2024-2036 · Otrs · Otrs

Matthias Püschel

·

Published

2024-01-29

·

Updated

2024-02-02

·

CVE-2024-23790

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.X through 7.0.48 OTRS versions 8.0.X through 8.0.37 OTRS versions 2023 through 2023.1.1
Description The issue is related to an Improper Input Validation vulnerability in the upload functionality for user avatars, which allows functionality misuse due to a missing check of filetypes. This vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations For OTRS versions 7.0.X through 7.0.48, update to a version later than 7.0.48. For OTRS versions 8.0.X through 8.0.37, update to a version later than 8.0.37. For OTRS versions 2023 through 2023.1.1, update to a version later than 2023.1.1. As a temporary workaround, consider disabling the upload functionality for user avatars until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-01914
CVE-2024-23790

Affected Products

Otrs