Information disclosure in OTRS - CVE-2017-15864
Published: November 24, 2017 / Updated: November 27, 2017
OTRS
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient input validation. A remote attacker who is logged into OTRS as an agent can request special URLs from OTRS, and retrieve any configuration information, including database credentials.