CVE-2024-23793

EUVD-2024-21246
The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts.
This issue affects OTRS: from 7.0.X through 7.0.49, 8.0.X, 2023.X, from 2024.X through 2024.3.2; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
otrsotrs
7.0.x ≤
𝑥
< 7.0.49
ADP
otrsotrs
2024.x ≤
𝑥
< 2024.3.2
ADP
otrsotrs_community_edition
6.0.1 ≤
𝑥
< 6.0.34
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
znuny
focal
dne
jammy
dne
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage