Loading HuntDB...

GHSA-295x-34p8-7q26

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has previously enabled the setting 'RequiredLock' of 'AgentFrontend::Ticket::InlineEditing::Property###Watch' in the system configuration.This issue affects OTRS: 

* 8.0.X
* 2023.X
* from 2024.X through 2024.4.x

Related CVEs

Key Information

GHSA ID
GHSA-295x-34p8-7q26
Published
July 15, 2024 9:36 AM
Last Modified
July 16, 2024 6:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.