Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-1767
HistoryJan 10, 2020 - 3:15 p.m.

Design/Logic Flaw

2020-01-1015:15:00
PRIOn knowledge base
www.prio-n.com
6

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

38.1%

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

38.1%