Spoofing of From field in several screens
Published Jan 10, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.45%
Description
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Affected products
-
Affected
- 7.0.x version 7.0.13 and prior versions
-
Affected
- 5.0.x version 5.0.39 and prior versions
- 6.0.x version 6.0.24 and prior versions
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
Configuration 1
Configuration 2
- 8.0
Configuration 3
- 15.0
- 15.0
- 15.0
- 15.1
- 15.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to OTRS 7.0.14, ((OTRS)) Community Edition 6.0.25, ((OTRS)) Community Edition 5.0.40
Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/d146d4997cbd6e1370669784c6a2ec8d64655252 Patch for ((OTRS)) Community Edition 5: https://github.com/OTRS/otrs/commit/874889b86abea4c01ceb1368a836b66694fae1c3
References (7)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html vendor-advisoryMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12591 Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00027.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html mailing-list
- https://otrs.com/release-notes/otrs-security-advisory-2020-01/ PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | vendor-advisoryMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | vendor-advisoryMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | vendor-advisoryMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12591 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/01/msg00027.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | mailing-list | |
| https://otrs.com/release-notes/otrs-security-advisory-2020-01/ | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data