An issue was discovered in Open Ticket Request System (OTRS) 7.0 through 7.0.6. An attacker who is logged into OTRS as a customer user can use the search result screens to disclose information from internal FAQ articles, a different vulnerability than CVE-2019-9753.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Otrs | Otrs | 7.0.0 (including) | 7.0.6 (including) |
Otrs2 | Ubuntu | bionic | * |
Otrs2 | Ubuntu | eoan | * |
Otrs2 | Ubuntu | groovy | * |
Otrs2 | Ubuntu | hirsute | * |
Otrs2 | Ubuntu | impish | * |
Otrs2 | Ubuntu | trusty | * |
Otrs2 | Ubuntu | xenial | * |