Loading HuntDB...

GHSA-4h85-vpxq-834q

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

When adding attachments to ticket comments,
another user can add attachments as well impersonating the orginal user. The attack requires a
logged-in other user to know the UUID. While the legitimate user
completes the comment, the malicious user can add more files to the
comment.

This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

Related CVEs

Key Information

GHSA ID
GHSA-4h85-vpxq-834q
Published
January 29, 2024 12:30 PM
Last Modified
January 29, 2024 12:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.