CVE Published: 18/10/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021 Source: OTRS |
Vendor: OTRS AG |
Product: OTRS Status : PUBLISHED
CVE-2021-36097 Description
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
Metrics
CVSS Version: 3.1 |
Base Score: 3.5 LOW Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N