First published: Mon Aug 09 2021(Updated: )
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=3.0.0<=3.0.21 | |
Otrs Otrs | >=3.1.0<=3.1.17 | |
Otrs Otrs | >=3.2.0<=3.2.8 | |
Otrs Otrs Itsm | >=3.0.0<=3.0.8 | |
Otrs Otrs Itsm | >=3.1.0<=3.1.9 | |
Otrs Otrs Itsm | >=3.2.0<=3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4717 is a vulnerability in the Open Ticket Request System (OTRS) Help Desk software that allows remote authenticated users to execute arbitrary SQL commands.
CVE-2013-4717 has a severity rating of 8.8 (high).
CVE-2013-4717 affects OTRS Help Desk versions 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9.
To fix CVE-2013-4717, you should upgrade your OTRS Help Desk software to version 3.0.22, 3.1.18, or 3.2.9.
You can find more information about CVE-2013-4717 at the following link: [https://web.archive.org/web/20130817120539/http://www.otrs.com/de/open-source/community-news/security-advisories/security-advisory-2013-05/](https://web.archive.org/web/20130817120539/http://www.otrs.com/de/open-source/community-news/security-advisories/security-advisory-2013-05/)