CVE-2010-0438: SQL Injection
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0438?
CVE-2010-0438 is classified as a medium severity vulnerability due to its potential for remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2010-0438?
To fix CVE-2010-0438, you should upgrade to the latest versions of OTRS that are not affected by this vulnerability, specifically versions 2.1.9, 2.2.9, 2.3.5, or 2.4.7 and later.
Who is affected by CVE-2010-0438?
CVE-2010-0438 affects multiple versions of OTRS prior to the specified patched releases, allowing remote authenticated users to exploit SQL injection vulnerabilities.
What types of vulnerabilities are described in CVE-2010-0438?
CVE-2010-0438 specifically describes multiple SQL injection vulnerabilities that can be exploited by remote authenticated users via unspecified vectors.
What are the key versions vulnerable to CVE-2010-0438?
Key vulnerable versions of OTRS include 2.1.3, 2.2.4, 2.3.4, and 2.4.6, prior to their respective fixed releases.