CVE-2023-38056

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*

History

21 Nov 2024, 08:12

Type Values Removed Values Added
References () https://otrs.com/release-notes/otrs-security-advisory-2023-05/ - Vendor Advisory () https://otrs.com/release-notes/otrs-security-advisory-2023-05/ - Vendor Advisory

01 Aug 2023, 17:00

Type Values Removed Values Added
References (MISC) https://otrs.com/release-notes/otrs-security-advisory-2023-05/ - (MISC) https://otrs.com/release-notes/otrs-security-advisory-2023-05/ - Vendor Advisory
CWE CWE-78
CPE cpe:2.3:a:otrs:otrs:*:*:*:*:-:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Otrs
Otrs otrs

24 Jul 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-24 09:15

Updated : 2024-11-21 08:12


NVD link : CVE-2023-38056

Mitre link : CVE-2023-38056

CVE.ORG link : CVE-2023-38056


JSON object : View

Products Affected

otrs

  • otrs
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')