OTRS是德国OTRS公司的一个服务管理解决方案。 OTRS存在安全漏洞,该漏洞源于具有管理员权限的攻击者对输入所做的不当无效化,允许在系统配置中针对其他管理员进行跨站脚本攻击。受影响版本如下:OTRS 7.0.X至7.0.50版本、OTRS 8.0.X版本、OTRS 2023.X版本、OTRS 2024.X至2024.5.X版本和OTRS Community Edition 6.0.x版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | OTRS | 7.0.x ~ 7.0.50 | - |
|
| OTRS AG | ((OTRS)) Community Edition | 6.0.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-43444 | 8.2 HIGH | Passwords are written to Admin Log Module |
| CVE-2024-43443 | 4.9 MEDIUM | Stored XSS in process management |
No comments yet