CVE-2023-38058 MEDIUM

CVE-2023-38058: Tickets can be moved without permissions

Vendor Otrs Ag
Product OTRS
Weakness CWE-269
Published July 24, 2023
Last update October 17, 2024

CVSS base score

4.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

Key dates

02Disclosure timeline

July 24, 2023 CVE published
October 17, 2024 Record updated