AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-12746

MEDIUM · CVSS 6.5 EPSS 2.02%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-12746
Severity
MEDIUM
CVSS
6.5
EPSS
2.02%

Original NVD Description

An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.