CVE-2008-7282: Medium severity OTRS OTRS vulnerability
Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7282?
CVE-2008-7282 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to information.
How do I fix CVE-2008-7282?
To fix CVE-2008-7282, upgrade to OTRS version 2.2.6 or later where the vulnerability has been addressed.
What software is affected by CVE-2008-7282?
CVE-2008-7282 affects multiple versions of the Open Ticket Request System (OTRS) prior to 2.2.6.
Can CVE-2008-7282 be exploited remotely?
Yes, CVE-2008-7282 can be exploited remotely by authenticated users to bypass access restrictions.
What options need to be enabled for CVE-2008-7282 to be a threat?
CVE-2008-7282 requires the CustomerPanelOwnSelection and CustomerGroupSupport options to be enabled to pose a threat.