CVE-2014-1694

OTRS 3.1.x < 3.1.19, 3.2.x < 3.2.14, 3.3.x < 3.3.4 - Cross-Site Request Forgery in Customer Ticket Modules

Title source: llm
STIX 2.1

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3) CustomerTicketProcess.pm, and (4) CustomerTicketZoom.pm in Kernel/Modules/ in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allow remote attackers to hijack the authentication of arbitrary users for requests that (5) create tickets or (6) send follow-ups to existing tickets.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102632
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/29/15
Various Sources x_refsource_confirm
https://www.otrs.com/release-notes-otrs-help-desk-3-3-4
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56655
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/29/7
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56644
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-2867
Various Sources x_refsource_confirm
http://bugs.otrs.org/show_bug.cgi?id=10099

Scores

EPSS 0.0148
EPSS Percentile 70.7%

Details

CWE
CWE-352
Status published
Products (33)
otrs/otrs 3.2.0 (7 CPE variants)
otrs/otrs 3.2.1
otrs/otrs 3.2.2
otrs/otrs 3.2.3
otrs/otrs 3.2.4
otrs/otrs 3.2.5
otrs/otrs 3.2.6
otrs/otrs 3.2.7
otrs/otrs 3.2.8
otrs/otrs 3.2.9
... and 23 more
Published Feb 04, 2014
Tracked Since Feb 18, 2026