In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2017/12/msg00015.html | third party advisory mailing list |
https://www.debian.org/security/2017/dsa-4066 | third party advisory vendor advisory |
https://www.otrs.com/security-advisory-2017-08-security-update-otrs-framework/ | broken link |