VYPR

((OTRS)) Community Edition

by OTRS

CVEs (54)

  • CVE-2019-12248MedJun 17, 2019
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could…

  • CVE-2023-38057MedJul 24, 2023
    risk 0.27cvss 4.1epss 0.00

    An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent.…

  • CVE-2025-24388LowJun 16, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X * …

  • CVE-2024-43446LowJan 27, 2025
    risk 0.23cvss 3.5epss 0.00

    An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community…

  • CVE-2023-5421LowOct 16, 2023
    risk 0.23cvss 3.5epss 0.00

    An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs immediatly after the data is saved.The issue onlyoccurs if the configuration for…

  • CVE-2022-39049LowSep 5, 2022
    risk 0.23cvss 3.5epss 0.01

    An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.

  • CVE-2021-36091LowJul 26, 2021
    risk 0.23cvss 3.5epss 0.01

    Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.

  • CVE-2021-21443LowJul 26, 2021
    risk 0.23cvss 3.5epss 0.01

    Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.

  • CVE-2020-1776LowJul 20, 2020
    risk 0.23cvss 3.5epss 0.01

    When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 and prior versions. OTRS: 7.0.18 and prior…

  • CVE-2020-1769LowMar 27, 2020
    risk 0.23cvss 3.5epss 0.01

    In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior…

  • CVE-2020-1767LowJan 10, 2020
    risk 0.23cvss 3.5epss 0.01

    Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community…

  • CVE-2020-1765LowJan 10, 2020
    risk 0.23cvss 3.5epss 0.01

    An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions;…

  • CVE-2020-1770LowMar 27, 2020
    risk 0.16cvss 2.4epss 0.01

    Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

  • CVE-2020-1766LowJan 10, 2020
    risk 0.13cvss 2.0epss 0.01

    Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version…

Page 3 of 3