Back to search
CVE-2017-16921
Published: Dec 8, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[debian-lts-announce] 20171219 [SECURITY] [DLA 1212-1] otrs2 security update
mailing-list
x_refsource_MLIST
43853
exploit
x_refsource_EXPLOIT-DB
DSA-4066
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now