NVD

Id
52160  
Name
CVE-2009-5056  
Description
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.  
Reject
 
CVSS Version
2  
CVSS Score
2.1  
Severity
Low  
CVSS Base Score
2.1  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
3.9  
CVSS Vector
(AV:N/AC:H/Au:S/C:P/I:N/A:N)  
Pub Date
2017-01-07  
Published
2011-03-18  
Modified Date
2011-03-22  
Seq
2009-5056  

Actions