Information disclosure in OTRS - CVE-2022-1004
Published: March 23, 2022
OTRS
otrs.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper restriction of the accounted time in the Ticket Detail View (External Interface) when ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled. A remote user can gain unauthorized access to sensitive information on the system.