ZeroHour

CVE-2017-17476

CVSS 3.0
8.8 high
EPSS
2%p82
Published
()
Modified
Description

Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.

Vendors
otrsdebian
Products
otrs, debian linux
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.