CVE-2019-18180

MEDIUM

OTRS 5.0.0-5.0.38 and 7.0.0-7.0.12 - Denial of Service via Long Filename Extension

Title source: llm
STIX 2.1

Description

Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.

Scores

CVSS v3 5.3
EPSS 0.0192
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-835
Status published
Products (2)
otrs/otrs 5.0.0 - 5.0.39
otrs/otrs 7.0.0 - 7.0.13
Published Dec 05, 2019
Tracked Since Feb 18, 2026