CVE-2017-17476

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-17476
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17476.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-17476
Downstream
Published
2017-12-20T17:29:00Z
Modified
2025-04-20T01:37:25Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.

References

Affected packages