CVE-2023-38056

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2023-07-24 09:15

Updated : 2023-08-01 17:00


NVD link : CVE-2023-38056

Mitre link : CVE-2023-38056

CVE.ORG link : CVE-2023-38056


JSON object : View

Products Affected

otrs

  • otrs
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')