CVE-2023-1250: Code execution through ACL creation
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-1250.
What is the severity of CVE-2023-1250?
The severity of CVE-2023-1250 is high, with a severity value of 7.8.
Which software is affected by CVE-2023-1250?
CVE-2023-1250 affects OTRS AG OTRS and OTRS AG Community Edition.
How can the vulnerability CVE-2023-1250 be exploited?
CVE-2023-1250 can be exploited by creating or importing an ACL with manipulated comments and ACL names that allow code execution.
Is there a fix available for CVE-2023-1250?
Yes, a fix is available for CVE-2023-1250. Please refer to the OTRS security advisory for more information.