Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Otrs | Otrs | 6.0.0 (including) | 6.0.32 (including) |
Otrs | Otrs | 7.0.0 (including) | 7.0.37 (excluding) |
Otrs | Otrs | 8.0.0 (including) | 8.0.25 (excluding) |
Znuny | Ubuntu | kinetic | * |
Znuny | Ubuntu | lunar | * |
Znuny | Ubuntu | mantic | * |
Znuny | Ubuntu | trusty | * |
Znuny | Ubuntu | xenial | * |