| |
Vulnerability CVE-2022-0474
Published: 2022-02-07
Description: |
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions. |
Type:
CWE-200 (Information Exposure)
CVSS2 => (AV:N/AC:M/Au:S/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
3.5/10 |
2.9/10 |
6.8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://otrs.com/release-notes/otrs-security-advisory-2022-02/
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|