VYPR

Otrs

by OTRS

Source repositories

CVEs (160)

  • CVE-2019-10066MedMay 22, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5.0.x through 5.0.12. An attacker who is logged into OTRS as an agent with appropriate permissions may create a carefully crafted…

  • CVE-2019-9752MedMar 13, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the…

  • CVE-2025-24391MedJul 14, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS…

  • CVE-2024-23794MedJul 15, 2024
    risk 0.34cvss 5.2epss 0.00

    An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has…

  • CVE-2024-23792MedJan 29, 2024
    risk 0.34cvss 5.3epss 0.00

    When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the …

  • CVE-2023-38059MedOct 16, 2023
    risk 0.34cvss 5.3epss 0.00

    The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition:…

  • CVE-2021-36096MedSep 6, 2021
    risk 0.34cvss 5.2epss 0.00

    Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior…

  • CVE-2021-21440MedJul 26, 2021
    risk 0.34cvss 5.2epss 0.01

    Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior…

  • CVE-2024-43443MedAug 26, 2024
    risk 0.32cvss 4.9epss 0.00

    Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: …

  • CVE-2024-43442MedAug 26, 2024
    risk 0.32cvss 4.9epss 0.00

    Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue…

  • CVE-2024-23791MedJan 29, 2024
    risk 0.32cvss 4.9epss 0.01

    Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

  • CVE-2025-24387MedMar 10, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read…

  • CVE-2019-9751MedMar 13, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to…

  • CVE-2018-19142MedNov 11, 2018
    risk 0.31cvss 4.8epss 0.01

    Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.

  • CVE-2018-19141MedNov 11, 2018
    risk 0.31cvss 4.8epss 0.01

    Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.

  • CVE-2022-39050MedSep 5, 2022
    risk 0.30cvss 4.6epss 0.00

    An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the…

  • CVE-2020-1771MedMar 27, 2020
    risk 0.30cvss 4.6epss 0.01

    Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior…

  • CVE-2018-11563MedJul 8, 2019
    risk 0.30cvss 4.6epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS customer panel application.

  • CVE-2026-6060MedApr 20, 2026
    risk 0.29cvss 4.5epss 0.00

    A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:  * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X…

  • CVE-2020-1774MedApr 28, 2020
    risk 0.29cvss 4.5epss 0.01

    When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior…

Page 4 of 8