← Back to CVEs
CVE-2020-1776
LOW3.5
Description
When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 and prior versions. OTRS: 7.0.18 and prior versions, 8.0.4. and prior versions.
CVE Details
CVSS v3.1 Score3.5
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published7/20/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
otrs:otrs
Weaknesses (CWE)
CWE-613CWE-613
References
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html(security@otrs.com)
https://otrs.com/release-notes/otrs-security-advisory-2020-13/(security@otrs.com)
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html(af854a3a-2127-422b-91ae-364da2661108)
https://otrs.com/release-notes/otrs-security-advisory-2020-13/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.