Back to search
CVE-2018-16587
Published: Sep 28, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/OTRS/otrs/commit/d9db0c6a15caafda7689320ecf61777993c33711
x_refsource_CONFIRM
DSA-4317
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20180926 [SECURITY] [DLA 1521-1] otrs2 security update
mailing-list
x_refsource_MLIST
https://github.com/OTRS/otrs/commit/a4a1a01f84fac7ab032570ee50b660e2ebb15c01
x_refsource_CONFIRM
https://github.com/OTRS/otrs/commit/d8cae00b0f78c2a07bb10cedb817304139395843
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now