Feed/CVE-2009-5056
CVE-2009-5056LOWCVSS 2.1

CVE-2009-5056

Published Mar 18, 2011·Updated Jun 16, 2026

NVD Description

Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.

CVSS Vector

AV:N/AC:H/Au:S/C:P/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free