HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-38056

CVSS 7.2v3.1pub. 2023-07-24upd. 2024-11-21

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Otrs

    APP
    Otrs
    6.0.1 – 6.0.347.0.0 – 7.0.45 (excl.)8.0.0 – 8.0.35 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-48188CRITICAL9.1PL ✓same product

OTRS / Community Edition: SQL injection z pominięciem uwierzytelnienia

CVE-2026-48209HIGH7.1same product

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling al...

CVE-2023-6254HIGH8.1same product

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which ...

CVE-2023-5422HIGH8.7same product

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL o...

CVE-2023-2534HIGH7.6same product

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticat...