{"id":"CVE-2023-1250","details":"Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names\nThis issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.\n\n","modified":"2026-03-14T12:01:01.105677Z","published":"2023-03-20T09:15:12.020Z","references":[{"type":"ADVISORY","url":"https://otrs.com/release-notes/otrs-security-advisory-2023-02/"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1250.json","unresolved_ranges":[{"events":[{"introduced":"6.0.1"},{"last_affected":"6.0.34"}]},{"events":[{"introduced":"7.0.0"},{"fixed":"7.0.42"}]},{"events":[{"introduced":"8.0.0"},{"fixed":"8.0.31"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}