Input validation error in OTRS - CVE-2018-20800

 

Input validation error in OTRS - CVE-2018-20800

Published: March 13, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36075
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-20800
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: otrs.org
Affected software:
OTRS

Detailed vulnerability description

The vulnerability allows a remote authenticated user to manipulate data.

An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table.


How to mitigate CVE-2018-20800

Install update from vendor's website.

Sources