First published: Fri Jan 10 2020(Updated: )
Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=6.0.0<=6.0.24 | |
OTRS | >=7.0.0<=7.0.13 | |
Debian GNU/Linux | =8.0 |
Upgrade to OTRS 7.0.14, ((OTRS)) Community Edition 6.0.25
Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/5f488fd6c809064ee49def3a432030258d211570
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1767 is classified as a medium severity vulnerability due to the potential for unauthorized message manipulation.
To fix CVE-2020-1767, upgrade OTRS to versions 6.0.25 or later, or 7.0.14 or later.
CVE-2020-1767 affects OTRS Community Edition versions 6.0.0 to 6.0.24 and 7.0.0 to 7.0.13.
CVE-2020-1767 is a message spoofing vulnerability that allows an unauthorized agent to send messages on behalf of another agent.
Yes, CVE-2020-1767 can significantly impact customer trust as customers may receive messages that are not from the intended sender.