← Back

CVE-2013-4717

nvd nist
Published: Aug 9, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm.

Affected (6)

Products: Otrs: Otrs, Otrs Itsm
2 products
Otrs
Otrs Itsm
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Otrs
From 3.0.0 to 3.0.21
From 3.1.0 to 3.1.17
From 3.2.0 to 3.2.8
Otrs
From 3.0.0 to 3.0.8
From 3.1.0 to 3.1.9
From 3.2.0 to 3.2.6

Timeline

No history available yet.