Description
The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-1438 | The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T22:28:41.311Z
Reserved: 2011-03-18T00:00:00.000Z
Link: CVE-2011-1433
No data.
Status : Modified
Published: 2011-03-18T16:55:01.720
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-1433
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD