AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-7567

HIGH · CVSS 7.2 EPSS 5.30% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-03-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-7567
Severity
HIGH
CVSS
7.2
EPSS
5.30%

Original NVD Description

In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a command on the server during package installation. NOTE: the vendor disputes this issue stating "the behaviour is as designed and needed for different packages to be installed", "there is a security warning if the package is not verified by OTRS Group", and "there is the possibility and responsibility of an admin to check packages before installation which is possible as they are not binary.

Related CVEs

Other vulnerabilities affecting the same vendor(s)