CVE-2023-38060

EUVD-2023-41886
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows  any authenticated attacker to  to perform an host header injection for the ContentType header of the attachment. 


This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
OTRSCNA
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
otrsotrs
6.0.1 ≤
𝑥
≤ 6.0.34
otrsotrs
7.0.0 ≤
𝑥
< 7.0.45
otrsotrs
8.0.0 ≤
𝑥
< 8.0.35
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
otrs2
bookworm
no-dsa
bullseye/non-free
vulnerable
znuny
bookworm
no-dsa
bookworm/non-free
vulnerable
bullseye
no-dsa
sid/non-free
6.5.11-1
fixed
trixie/non-free
6.5.11-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
otrs2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
dne
mantic
dne
noble
dne
oracular
dne
xenial
needs-triage
znuny
bionic
ignored
focal
dne
jammy
dne
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
ignored
xenial
ignored