CVE-2018-16587
Title: Otrs Open Ticket Request System Improper Input Validation
Improper Input Validation
Proof Of Concept
No public PoC currently indexed for CVE-2018-16587.
CWE Category
CWE-20
Published Date
Sep 28, 2018
Modified Date
Nov 21, 2024
Exploit Status
Not Found
Score
6.5
CVSS v3.0
Exploit Probability (EPSS)
1.75%
Vulnerability Summary
CVE-2018-16587: In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
Impacted Vendors
Reference Links
https://community.otrs.com/security-advisory-2018-04-security-update-for-otrs-framework/
https://github.com/OTRS/otrs/commit/a4a1a01f84fac7ab032570ee50b660e2ebb15c01
https://github.com/OTRS/otrs/commit/d8cae00b0f78c2a07bb10cedb817304139395843
https://github.com/OTRS/otrs/commit/d9db0c6a15caafda7689320ecf61777993c33711
https://lists.debian.org/debian-lts-announce/2018/09/msg00033.html
https://www.debian.org/security/2018/dsa-4317
https://community.otrs.com/security-advisory-2018-04-security-update-for-otrs-framework/
https://github.com/OTRS/otrs/commit/a4a1a01f84fac7ab032570ee50b660e2ebb15c01
https://github.com/OTRS/otrs/commit/d8cae00b0f78c2a07bb10cedb817304139395843
https://github.com/OTRS/otrs/commit/d9db0c6a15caafda7689320ecf61777993c33711
https://lists.debian.org/debian-lts-announce/2018/09/msg00033.html
https://www.debian.org/security/2018/dsa-4317
CVSS v3.0
Source Entity
[email protected]
Severity
MEDIUM
6.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:N/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2018-16587 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
CVSS Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Stack
No specific products linked.