cve/2024/CVE-2024-6540.md
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2024-6540

Description

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator.This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

POC

Reference

Github

No PoCs found on GitHub currently.