← back
CVE-2017-16921

CVE-2017-16921

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 20%
from disclosure to weapon44 days
Published on NVDDec 8
1st PoC+44d
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.