CVE-2018-14593

Source
https://cve.org/CVERecord?id=CVE-2018-14593
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14593.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-14593
Downstream
Published
2018-08-04T01:29:03.997Z
Modified
2026-03-14T14:32:29.856246Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14593.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "4.0.0"
            },
            {
                "last_affected": "4.0.30"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.0.0"
            },
            {
                "last_affected": "5.0.28"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.0.0"
            },
            {
                "last_affected": "6.0.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    }
]