CVE-2019-18180

MEDIUM

Otrs < 5.0.39 - Infinite Loop

Title source: rule
STIX 2.1

Description

Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.

Scores

CVSS v3 5.3
EPSS 0.0133
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-835
Status published
Products (2)
otrs/otrs 5.0.0 - 5.0.39
otrs/otrs 7.0.0 - 7.0.13
Published Dec 05, 2019
Tracked Since Feb 18, 2026