Vulnerability identifier: #VU31199
Vulnerability risk: Medium
CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-20
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
OTRS
Web applications /
Other software
Vendor: otrs.org
Description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
Mitigation
Install update from vendor's website.
Vulnerable software versions
OTRS: 6.0.0 - 6.0.10
External links
http://community.otrs.com/security-advisory-2018-04-security-update-for-otrs-framework/
http://github.com/OTRS/otrs/commit/a4a1a01f84fac7ab032570ee50b660e2ebb15c01
http://github.com/OTRS/otrs/commit/d8cae00b0f78c2a07bb10cedb817304139395843
http://github.com/OTRS/otrs/commit/d9db0c6a15caafda7689320ecf61777993c33711
http://lists.debian.org/debian-lts-announce/2018/09/msg00033.html
http://www.debian.org/security/2018/dsa-4317
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.