First published: Mon Jan 29 2024(Updated: )
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=7.0.0<7.0.49 | |
OTRS | >=8.0.0<2024.1.1 |
Update to OTRS Patch 2024.1.1 Update to OTRS 7.0.49 (Long Term Support Users)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23790 has been classified with a medium severity level due to improper input validation in the avatar upload functionality.
To fix CVE-2024-23790, upgrade OTRS to versions 7.0.49, 8.0.38, or 2024.1.1 to ensure proper checks for file types are implemented.
CVE-2024-23790 affects OTRS versions from 7.0.0 to 7.0.48, 8.0.0 to 8.0.37, and the 2023 version.
CVE-2024-23790 is classified as an improper input validation vulnerability related to user avatar uploads.
Yes, CVE-2024-23790 can lead to functionality misuse due to the lack of file type checks during the avatar upload process.