CVE-2020-1765
LOWOTRS <5.0.39, <6.0.24, <7.0.13 - Info Disclosure
Title source: llmDescription
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.
References (6)
Scores
CVSS v3
3.5
EPSS
0.0063
EPSS Percentile
70.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-472
Status
published
Affected Products (8)
otrs/otrs
< 5.0.39
otrs/otrs
< 7.0.13
debian/debian_linux
opensuse/backports_sle
opensuse/backports_sle
opensuse/backports_sle
opensuse/leap
opensuse/leap
Timeline
Published
Jan 10, 2020
Tracked Since
Feb 18, 2026