Back to search
CVE-2010-4768
Published: Mar 18, 2011
Modified: Sep 16, 2024
PUBLISHED
Description
Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circumstances by visiting a ticket, related to a certain ordering of permission-set and permission-remove operations involving both hidden permissions and other permissions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.otrs.org/show_bug.cgi?id=3499
x_refsource_CONFIRM
http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now