Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
References
Link Resource
http://advisories.mageia.org/MGASA-2013-0196.html Third Party Advisory
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-3551 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-02-21T15:35:41

Updated: 2020-02-21T15:35:41

Reserved: 2013-05-16T00:00:00


Link: CVE-2013-3551

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-21T16:15:11.327

Modified: 2020-02-26T19:34:22.890


Link: CVE-2013-3551

JSON object: View

cve-icon Redhat Information

No data.

CWE