Lucene search

K
cve[email protected]CVE-2023-38060
HistoryJul 24, 2023 - 9:15 a.m.

CVE-2023-38060

2023-07-2409:15:10
CWE-74
CWE-20
web.nvd.nist.gov
28
otrs
generic interface
input validation
vulnerability
cve-2023-38060
nvd
host header injection

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.001

Percentile

24.3%

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the ContentType header of the attachment.

This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

Affected configurations

NVD
Node
otrsotrsRange6.0.16.0.34community
OR
otrsotrsRange7.0.07.0.45-
OR
otrsotrsRange8.0.08.0.35-
VendorProductVersionCPE
otrsotrscpe:/a:otrs:otrs:::community:

CNA Affected

[
  {
    "defaultStatus": "affected",
    "modules": [
      "Generic Interface"
    ],
    "product": "OTRS",
    "vendor": "OTRS AG",
    "versions": [
      {
        "lessThan": "7.0.45",
        "status": "affected",
        "version": "7.0.x",
        "versionType": "Patch"
      },
      {
        "lessThan": "8.0.35",
        "status": "affected",
        "version": "8.0.x",
        "versionType": "Patch"
      }
    ]
  },
  {
    "defaultStatus": "affected",
    "modules": [
      "Generic Interface"
    ],
    "product": "((OTRS)) Community Edition",
    "vendor": "OTRS AG",
    "versions": [
      {
        "lessThanOrEqual": "6.0.34",
        "status": "affected",
        "version": "6.0.1",
        "versionType": "All"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.001

Percentile

24.3%