TROYANOSYVIRUS
Voltar para CVEs

CVE-2008-7277

N/A

Descricao

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado3/18/2011
Ultima modificacao4/29/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

otrs:otrs

Fraquezas (CWE)

CWE-264

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.