Back to search
CVE-2011-1433
Published: Mar 18, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.otrs.org/show_bug.cgi?id=6878
x_refsource_CONFIRM
otrs-agentinterface-info-disc(66196)
vdb-entry
x_refsource_XF
http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now