PT-2025-2648 · Otrs · Otrs
Published
2025-01-27
·
Updated
2025-01-27
·
CVE-2024-43446
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS versions 6.0.x through 8.0.x
OTRS versions 2023.x through 2024.x
Description
An improper privilege management issue in the OTRS Generic Interface module allows users with read-only permissions to change the ticket status. This issue may affect products based on the OTRS Community Edition.
Recommendations
For OTRS versions 6.0.x, consider restricting access to the Generic Interface module until a fix is available.
For OTRS versions 7.0.x, 8.0.x, 2023.x, and 2024.x, restrict the use of the Generic Interface module to minimize the risk of exploitation.
As a temporary workaround, consider disabling the functionality that allows ticket status changes through the Generic Interface module until a patch is available.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otrs