CVE-2019-9753

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/06/2019
Last modified:
09/10/2019

Description

An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an agent or a customer user can use the search result screens to disclose information from invalid system entities. Following is the list of affected entities: Custom Pages, FAQ Articles, Service Catalogue Items, ITSM Configuration Items.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.5 (excluding)