CVE-2024-6540
CVE-2024-6540
Título es
CVE-2024-6540
Lun, 15/07/2024 – 08:15
Tipo
CWE-790
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-6540
Descripción en
Improper filtering of fields when using the export function in the ticket overview of the external interface could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator.
This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x
This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x
15/07/2024
15/07/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
5.70
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Enviar en el boletín
Off
