Input validation error in OTRS - CVE-2018-20800
Published: March 13, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU36075
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20800
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to manipulate data.
An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table.
Affected software
OTRS
otrs (Alpine package)
otrs (Alpine package)
How to mitigate CVE-2018-20800
Install update from vendor's website.
otrs (Alpine package) - update to 6.0.33-r0