CVE-2010-4761
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
18/03/2011
Last modified:
11/04/2025
Description
The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.
Impact
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:otrs:otrs:*:beta2:*:*:*:*:*:* | 3.0.0 (including) | |
| cpe:2.3:a:otrs:otrs:0.5:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta7:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta8:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



