CVE-2010-4763
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
18/03/2011
Last modified:
11/04/2025
Description
The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.
Impact
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* | 2.4.10 (including) | |
| cpe:2.3:a:otrs:otrs:0.5:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta7:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:0.5:beta8:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:otrs:otrs:1.0.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



