Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes.
This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.
References
Link | Resource |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2024-01/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: OTRS
Published: 2024-01-29T09:21:14.996Z
Updated: 2024-01-29T09:21:14.996Z
Reserved: 2024-01-22T10:32:00.704Z
Link: CVE-2024-23790
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-29T10:15:08.263
Modified: 2024-02-02T02:07:58.653
Link: CVE-2024-23790
JSON object: View
Redhat Information
No data.