VYPR

Otrs

by OTRS

Source repositories

CVEs (160)

  • CVE-2025-24390MedJan 27, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X

  • CVE-2022-39051MedSep 5, 2022
    risk 0.44cvss 6.8epss 0.01

    Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

  • CVE-2026-48208MedJun 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets…

  • CVE-2022-4427MedDec 19, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1…

  • CVE-2021-36100MedMar 21, 2022
    risk 0.42cvss 6.4epss 0.01

    Specially crafted string in OTRS system configuration can allow the execution of any system command.

  • CVE-2021-36092MedJul 26, 2021
    risk 0.42cvss 6.5epss 0.01

    It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version…

  • CVE-2021-21439MedJun 14, 2021
    risk 0.42cvss 6.5epss 0.01

    DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1…

  • CVE-2020-1772MedMar 27, 2020
    risk 0.42cvss 6.5epss 0.02

    It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior…

  • CVE-2013-4088MedFeb 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL…

  • CVE-2013-3551MedFeb 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote…

  • CVE-2019-13458MedAug 21, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in…

  • CVE-2019-12746MedAug 21, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties.…

  • CVE-2019-9892MedMay 22, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will…

  • CVE-2018-20800MedMar 13, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table.

  • CVE-2018-19143MedNov 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.

  • CVE-2018-16587MedSep 28, 2018
    risk 0.42cvss 6.5epss 0.02

    In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has…

  • CVE-2017-16854MedDec 8, 2017
    risk 0.42cvss 6.5epss 0.01

    In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.

  • CVE-2025-24389MedJan 27, 2025
    risk 0.41cvss 6.3epss 0.00

    Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS))…

  • CVE-2024-23793MedJun 6, 2024
    risk 0.41cvss 6.3epss 0.01

    The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of…

  • CVE-2023-38060MedJul 24, 2023
    risk 0.41cvss 6.3epss 0.01

    Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the ContentType header of the…

Page 2 of 8