First published: Fri Aug 03 2018(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/otrs2 | 6.0.16-2 6.0.16-2+deb10u1 6.0.32-6 | |
OTRS | >=4.0.0<=4.0.30 | |
OTRS | >=5.0.0<=5.0.28 | |
OTRS | >=6.0.0<=6.0.9 | |
Debian | =8.0 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14593 is considered a critical privilege escalation vulnerability.
To mitigate CVE-2018-14593, upgrade OTRS to version 6.0.16-2 or later.
CVE-2018-14593 affects OTRS versions from 4.0.x up to 4.0.30, 5.0.x up to 5.0.28, and 6.0.x up to 6.0.9.
An attacker who is already logged in as an agent in OTRS can exploit CVE-2018-14593.
CVE-2018-14593 impacts OTRS installations on Debian Linux versions 8.0 and 9.0.