CVE-2024-6540

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator. This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-15 08:15

Updated : 2024-07-16 18:05


NVD link : CVE-2024-6540

Mitre link : CVE-2024-6540

CVE.ORG link : CVE-2024-6540


JSON object : View

Products Affected

otrs

  • otrs
CWE
NVD-CWE-noinfo CWE-790

Improper Filtering of Special Elements