Description


Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

Related CPE's


Vulnerable

Weaknesses



CWE-266


NVD-CWE-noinfo

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

3.5 · Low

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-10-18T05:15:07.413Z

4 years ago

Last modified

2024-11-21T05:13:09.143Z

1 year ago