CVE-2008-7277

EPSS 0.20%
發布日:2011/3/18修改日:2026/4/28

描述

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

受影響套件(1)

參考連結(1)