CVE-2010-4758
EPSS 0.06%
Description
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
How to fix CVE-2010-4758
To remediate CVE-2010-4758, upgrade the affected package to a fixed version below.
- Debian/otrs2—upgrade to 3.0.8+dfsg1-1 or later
Is CVE-2010-4758 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.0.8+dfsg1-1