Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Disclosure of mail addresses
Vulnerability Description
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
OTRS 信息泄露漏洞
Vulnerability Description
OTRS AG OTRS Custom Contact Fields是德国OTRS公司的OTRS自定义联系人字段插件。 OTRS AG OTRS Custom Contact Fields 存在信息泄露漏洞,该漏洞源于当通知被设置为单独发送给每个收件人时,可以在通知电子邮件事件中披露来自客户用户的联系人字段中的完整收件人列表。
CVSS Information
N/A
Vulnerability Type
N/A