Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_ticket_request_system | Otrs | 4.0.0 (including) | 4.0.33 (excluding) |
Open_ticket_request_system | Otrs | 5.0.0 (including) | 5.0.31 (excluding) |
Open_ticket_request_system | Otrs | 6.0.0 (including) | 6.0.13 (excluding) |
Otrs2 | Ubuntu | bionic | * |
Otrs2 | Ubuntu | cosmic | * |
Otrs2 | Ubuntu | esm-apps/bionic | * |
Otrs2 | Ubuntu | esm-apps/xenial | * |
Otrs2 | Ubuntu | trusty | * |
Otrs2 | Ubuntu | upstream | * |
Otrs2 | Ubuntu | xenial | * |