#VU42078 Cross-site request forgery in OTRS - CVE-2014-1694
Published: February 4, 2014 / Updated: August 10, 2020
OTRS
otrs.org
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Remediation
External links
- http://bugs.otrs.org/show_bug.cgi?id=10099
- http://osvdb.org/102632
- http://secunia.com/advisories/56644
- http://secunia.com/advisories/56655
- http://www.debian.org/security/2014/dsa-2867
- http://www.openwall.com/lists/oss-security/2014/01/29/15
- http://www.openwall.com/lists/oss-security/2014/01/29/7
- https://github.com/OTRS/otrs/commit/6f324aaf8647729d509eebf063a0181f9f9196f7
- https://github.com/OTRS/otrs/commit/92f417277f43832f1a0462f2485fe1fd3fd52312
- https://github.com/OTRS/otrs/commit/ca2c3390fd60d9a3f810ed2c22cbc2c193457b77
- https://www.otrs.com/release-notes-otrs-help-desk-3-3-4
- https://www.otrs.com/security-advisory-2014-01-csrf-issue-customer-web-interface