CVE-2013-3551
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets,…
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- otrs/otrs · otrs/otrs itsm
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2013-0196.htmlThird Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-3551Issue Tracking, Third Party Advisory
- http://advisories.mageia.org/MGASA-2013-0196.htmlThird Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-3551Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.