CVE-2020-1765: Spoofing of From field in several screens
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRS 7.0.xto a version that resolves this vulnerability.Fixed in 7.0.14 - Upgrade
Upgrade
OTRS Community Edition 6.0.xto a version that resolves this vulnerability.Fixed in 6.0.25 - Upgrade
Upgrade
OTRS Community Edition 5.0.xto a version that resolves this vulnerability.Fixed in 5.0.40
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1765?
CVE-2020-1765 is classified as a high-severity vulnerability due to its potential for email spoofing.
How do I fix CVE-2020-1765?
To mitigate CVE-2020-1765, users should upgrade to the latest version of OTRS that addresses this vulnerability.
What affected systems are associated with CVE-2020-1765?
CVE-2020-1765 affects OTRS Community Edition versions 5.0.39 and earlier, 6.0.24 and earlier, and 7.0.13 and earlier.
Can CVE-2020-1765 be exploited remotely?
Yes, CVE-2020-1765 can be exploited remotely, allowing attackers to spoof email headers.
What types of systems are vulnerable to CVE-2020-1765?
Systems running affected versions of OTRS, Debian Linux, and openSUSE Backports are vulnerable to CVE-2020-1765.