← Back to CVE List
Vulnerability Intelligence Report
Code execution through ACL creation

CVE-2023-1250

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

No Active Exploit Signals
CVSS Base Score
7.4
HIGH
Exploitability:1.1
Impact Score:5.8
EPSS Probability:0.29%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
OTRS AG OTRS 7.0.x < 7.0.42 (affected), 8.0.x < 8.0.31 (affected)
OTRS AG ((OTRS)) Community Edition 6.0.1 <= 6.0.34 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.295%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityOTRS AG · Vendor · Germany
Reserved2023-03-07T09:36:16
Published2023-03-20T08:20:39
Patch Date2023-03-20
Last Updated2025-02-26T19:20:36

LINK COPIED TO CLIPBOARD