CVE-2010-4760: Infoleak
Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4760?
CVE-2010-4760 is considered to have a medium severity level because it allows remote authenticated users to access potentially sensitive information.
How do I fix CVE-2010-4760?
To fix CVE-2010-4760, upgrade your OTRS installation to version 3.0.0-beta6 or later.
Who is affected by CVE-2010-4760?
CVE-2010-4760 affects OTRS versions prior to 3.0.0-beta6, allowing certain authenticated users to exploit the vulnerability.
What kind of information can be exposed by CVE-2010-4760?
CVE-2010-4760 may allow unauthorized access to ticket-related articles that could contain sensitive data.
Is CVE-2010-4760 fixed in the latest version of OTRS?
Yes, CVE-2010-4760 is fixed in OTRS versions 3.0.0-beta6 and above.