CVE-2023-1250
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules)
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31.
((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
HIGH · CVSS 7.4
EPSS 0.0015
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0