Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes.
This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-21243 Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.
Fixes

Solution

Update to OTRS Patch 2024.1.1 Update to OTRS 7.0.49 (Long Term Support Users)


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: OTRS

Published:

Updated: 2025-06-17T21:29:17.700Z

Reserved: 2024-01-22T10:32:00.704Z

Link: CVE-2024-23790

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-01-29T10:15:08.263

Modified: 2024-11-21T08:58:25.423

Link: CVE-2024-23790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.