PT-2024-37700 · Otrs · Otrs
Published
2024-07-15
·
Updated
2024-07-16
·
CVE-2024-6540
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS versions 8.0.X through 2024.4.x
OTRS version 2023.X
Description
The issue is related to improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS. This could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the
TicketSearchLegacyEngine has been disabled by the administrator.Recommendations
For OTRS versions 8.0.X through 2024.4.x, consider disabling the export function in the ticket overview of the external interface until a patch is available.
For OTRS version 2023.X, consider disabling the export function in the ticket overview of the external interface until a patch is available.
As a temporary workaround, consider enabling the
TicketSearchLegacyEngine to prevent the issue from occurring.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otrs