CVE-2017-16664
—CVSS 3.0
8.8 high
EPSS
2%p84
Published
()
Modified
Description
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.
In the news0 stories
No ingested article mentions this CVE yet.