OTRS Install Dialog Disclosure
Posted by deepcore on June 9, 2017 – 3:19 pm
Due to insufficient checking of privileges, it is possible to access the OTRS Install dialog of an already installed instance, which enables an authenticated attacker to change the database settings, superuser password, mail server settings, log file location and other parameters. Versions affected include OTRS 5.0.x, OTRS 4.0.x, and OTRS 3.3.x.
Post a reply
You must be logged in to post a comment.