OTRS是德国OTRS公司的一个服务管理解决方案。 OTRS存在安全漏洞,该漏洞源于缺少HTTPS会话中敏感cookie设置的属性,OTRS应用程序服务器和反向代理设置中的漏洞允许会话劫持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-24389 | 6.3 MEDIUM | SMTP Password will be shown in cleartext on some SMTP errors |
| CVE-2024-43445 | 5.4 MEDIUM | Missing X-Content-Type-Options: nosniff Header Allows MIME Type Sniffing |
| CVE-2024-43446 | 3.5 LOW | Improper check of permissions in Generic Interface |
No comments yet