OTRS ITSM是德国OTRS公司的一套IT服务管理组织的基础解决方案。该方案以ITIL最佳实践为基础,提供请求和故障管理、问题管理、变更管理和发布管理的管理工具。 OTRS AG OTRS 中存在信息泄露漏洞,该漏洞源于当客户通过外部接口打印票据(PDF)时,将显示文章密件字段和代理人个人信息。以下产品及型号受到影响:OTRS AG OTRS 7.0.x、7.0.23和以前的版本、8.0。x版本、8.0.10和以前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-1779 | 4.3 MEDIUM | Dynamic templates reveal sensitive data when OTRS tags are used |
| CVE-2021-21434 | 3.5 LOW | XSS in Survey Module |
| CVE-2021-21436 | 3.5 LOW | Agent is able to link customer's Config Items without permission |
No comments yet