VYPR

Otrs

by OTRS

Source repositories

CVEs (160)

  • CVE-2018-17883MedApr 16, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

  • CVE-2023-1248MedMar 20, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through…

  • CVE-2017-9299MedMay 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20…

  • CVE-2016-9139MedFeb 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.

  • CVE-2026-48189MedJun 1, 2026
    risk 0.37cvss 5.7epss 0.00

    An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected. This issue affects…

  • CVE-2026-48187MedJun 1, 2026
    risk 0.37cvss 5.7epss 0.00

    An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS: * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X …

  • CVE-2026-48210MedMay 31, 2026
    risk 0.37cvss 5.7epss 0.00

    An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the…

  • CVE-2024-6540MedJul 15, 2024
    risk 0.37cvss 5.7epss 0.00

    Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the…

  • CVE-2021-36094MedSep 6, 2021
    risk 0.37cvss 5.7epss 0.01

    It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

  • CVE-2021-21435MedFeb 8, 2021
    risk 0.37cvss 5.7epss 0.01

    Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.

  • CVE-2024-43445MedJan 27, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different MIME type than intended.…

  • CVE-2022-32741MedJun 13, 2022
    risk 0.35cvss 5.3epss 0.01

    Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

  • CVE-2021-36095MedSep 6, 2021
    risk 0.35cvss 5.3epss 0.01

    Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

  • CVE-2021-36093MedSep 6, 2021
    risk 0.35cvss 5.3epss 0.01

    It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15…

  • CVE-2013-4718MedAug 9, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.

  • CVE-2019-16375MedMar 19, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string…

  • CVE-2020-1768MedFeb 7, 2020
    risk 0.35cvss 5.4epss 0.01

    The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

  • CVE-2019-18180MedDec 5, 2019
    risk 0.35cvss 5.3epss 0.02

    Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community…

  • CVE-2019-12497MedJun 17, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be…

  • CVE-2019-10067MedMay 22, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.35 and 6.0.x through 6.0.17. An attacker who is logged into OTRS as an agent user with appropriate permissions may manipulate the URL to cause execution of…

Page 3 of 8