Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
Solution:
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
Link | Tags |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2022-12/ | vendor advisory |