CVE-2020-1767: Possible to send drafted messages as wrong agent
Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRS Community Editionto a version that resolves this vulnerability.Fixed in 7.0.14 - Upgrade
Upgrade
OTRS Community Editionto a version that resolves this vulnerability.Fixed in 6.0.25
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1767?
CVE-2020-1767 is classified as a medium severity vulnerability due to the potential for unauthorized message manipulation.
How do I fix CVE-2020-1767?
To fix CVE-2020-1767, upgrade OTRS to versions 6.0.25 or later, or 7.0.14 or later.
What software is affected by CVE-2020-1767?
CVE-2020-1767 affects OTRS Community Edition versions 6.0.0 to 6.0.24 and 7.0.0 to 7.0.13.
What kind of vulnerability is CVE-2020-1767?
CVE-2020-1767 is a message spoofing vulnerability that allows an unauthorized agent to send messages on behalf of another agent.
Can CVE-2020-1767 impact customer trust?
Yes, CVE-2020-1767 can significantly impact customer trust as customers may receive messages that are not from the intended sender.