CVE-2019-12746
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.
Se descubrió un problema en el Open Ticket Request System (OTRS) Community Edition 5.0.x hasta 5.0.36 y 6.0.x hasta 6.0.19. Un usuario que inició sesión en OTRS como agente podría revelar sin saberlo su ID de sesión al compartir el enlace de un artículo de ticket incrustado con terceros. Este identificador puede ser potencialmente abusado para suplantar al usuario del agente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-06-06 CVE Reserved
- 2019-08-21 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2019/08/msg00018.html | Mailing List | |
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | Mailing List | |
https://www.otrs.com/category/release-and-security-notes-en | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.otrs.com/security-advisory-2019-10-security-update-for-otrs-framework | 2023-08-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | >= 5.0.0 <= 5.0.36 Search vendor "Otrs" for product "Otrs" and version " >= 5.0.0 <= 5.0.36" | community |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | >= 6.0.0 <= 6.0.19 Search vendor "Otrs" for product "Otrs" and version " >= 6.0.0 <= 6.0.19" | community |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|