First published: Mon Jul 24 2023(Updated: )
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Credit: security@otrs.com security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.1<=6.0.34 | |
Otrs Otrs | >=7.0.0<7.0.45 | |
Otrs Otrs | >=8.0.0<8.0.35 |
Update to OTRS 8.0.35 or OTRS 7.0.45
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38056 is a vulnerability that allows any authenticated attacker with admin privileges to locally execute code in the OTRS system.
The severity of CVE-2023-38056 is high with a CVSS score of 7.2.
CVE-2023-38056 affects OTRS versions 6.0.1 to 6.0.34, 7.0.0 to 7.0.45, and 8.0.0 to 8.0.35.
An attacker with admin privileges can exploit CVE-2023-38056 by executing commands via the OTRS System Configuration, such as the SchedulerCronTaskModule using UnitTests modules.
To fix CVE-2023-38056, you should update OTRS to version 6.0.35, 7.0.46, or 8.0.36, as recommended by the vendor.