OTRS Install Dialog Disclosure

Discussion in 'News Aggregator' started by Packet Storm, 9 Jun 2017.

  1. Packet Storm

    Packet Storm Guest

    Due to insufficient checking of privileges, it is possible to access the OTRS Install dialog of an already installed instance, which enables an authenticated attacker to change the database settings, superuser password, mail server settings, log file location and other parameters. Versions affected include OTRS 5.0.x, OTRS 4.0.x, and OTRS 3.3.x.

    Continue reading...
     

Share This Page

Loading...