Loading HuntDB...

GHSA-4h57-3gmx-g682

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Improper filtering of fields when using the export function in the ticket overview of the external interface could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator.
This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

Related CVEs

Key Information

GHSA ID
GHSA-4h57-3gmx-g682
Published
July 15, 2024 9:36 AM
Last Modified
July 15, 2024 9:36 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.