#VU51866 Information disclosure in OTRS - CVE-2020-1769

 

#VU51866 Information disclosure in OTRS - CVE-2020-1769

Published: March 27, 2020 / Updated: April 1, 2021


Vulnerability identifier: #VU51866
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-1769
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OTRS
Software vendor:
otrs.org

Description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.


Remediation

Install update from vendor's website.

External links