CVE-2010-4763: Medium severity OTRS OTRS vulnerability
The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4763?
The severity of CVE-2010-4763 is considered medium as it allows authenticated users to bypass ACL restrictions.
How do I fix CVE-2010-4763?
To fix CVE-2010-4763, you should upgrade to OTRS version 3.0.0-beta1 or later.
What software versions are affected by CVE-2010-4763?
CVE-2010-4763 affects multiple OTRS versions, specifically all versions prior to 3.0.0-beta1.
What kind of vulnerability is CVE-2010-4763?
CVE-2010-4763 is an access control vulnerability that allows unauthorized ticket access.
Can CVE-2010-4763 affect customer data?
Yes, CVE-2010-4763 can potentially expose customer ticket data and status to unauthorized users.