I
mproper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.
References
| Link | Resource |
|---|---|
| https://otrs.com/release-notes/otrs-security-advisory-2024-01/ | Vendor Advisory |
| https://otrs.com/release-notes/otrs-security-advisory-2024-01/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://otrs.com/release-notes/otrs-security-advisory-2024-01/ - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.5 |
Information
Published : 2024-01-29 10:15
Updated : 2024-11-21 08:58
NVD link : CVE-2024-23790
Mitre link : CVE-2024-23790
CVE.ORG link : CVE-2024-23790
JSON object : View