Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Code execution through ACL creation
Vulnerability Description
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
OTRS 代码注入漏洞
Vulnerability Description
OTRS是德国OTRS公司的一个应用软件。一个服务管理软件。 OTRS AG OTRS (ACL modules)、OTRS AG ((OTRS)) Community Edition (ACL modules)存在安全漏洞,该漏洞源于输入验证不当。攻击者利用该漏洞可以本地执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A