First published: Mon Jul 24 2023(Updated: )
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.
Credit: security@otrs.com security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=8.0.0<8.0.35 |
Update to OTRS 8.0.35
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38058 is an improper privilege check vulnerability in the OTRS ticket move action in the agent interface.
CVE-2023-38058 allows any authenticated attacker to perform a ticket move without the necessary permission.
CVE-2023-38058 has a severity of medium with a CVSS score of 4.3.
CVE-2023-38058 affects OTRS versions 8.0.X before 8.0.35.
To fix CVE-2023-38058, it is recommended to upgrade OTRS to version 8.0.35 or later.