CVE-2010-4758: Low severity otrs vulnerability
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4758?
CVE-2010-4758 has a medium severity level due to the risk of password exposure through screen visibility.
How do I fix CVE-2010-4758?
To fix CVE-2010-4758, upgrade to OTRS version 3.0.3 or later, which addresses the vulnerability.
Which versions are affected by CVE-2010-4758?
CVE-2010-4758 affects multiple versions of OTRS prior to 3.0.3, including 2.4.0-beta6 through 2.4.0-beta3.
What type of vulnerability is CVE-2010-4758?
CVE-2010-4758 is a type of unintentional disclosure vulnerability allowing password visibility.
Who is affected by CVE-2010-4758?
Users of OTRS versions before 3.0.3 are at risk of having their passwords exposed to nearby individuals.