OTRS 社区版在其 PGP 加密模块中存在一个经过身份验证的操作系统命令注入漏洞。攻击者通过提供构造的 PGP 二进制文件路径和命令参数,能够以管理员身份执行任意操作系统命令。管理员输入的配置文件值未经过任何清理或过滤,就被直接拼接进 shell 命令中,从而导致任意命令执行。在恶意配置部署之后,即使是在正常的工单处理过程中,攻击者也可以以 Web 服务器进程的用户身份执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Centuran Consulting | OTRS Community Edition | ≤ 6.0.41 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Centuran Consulting | OTRS Community Edition | 0 ~ 6.0.41 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet