CVE-2023-38056

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*

History

01 Aug 2023, 17:00

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
References (MISC) https://otrs.com/release-notes/otrs-security-advisory-2023-05/ - (MISC) https://otrs.com/release-notes/otrs-security-advisory-2023-05/ - Vendor Advisory
First Time Otrs
Otrs otrs
CPE cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*

24 Jul 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-24 09:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-38056

Mitre link : CVE-2023-38056

CVE.ORG link : CVE-2023-38056


JSON object : View

Products Affected

otrs

  • otrs
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')