VYPR

Otrs

by OTRS

Source repositories

CVEs (160)

  • CVE-2022-1004MedMar 21, 2022
    risk 0.28cvss 4.3epss 0.01

    Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.

  • CVE-2020-1777MedOct 15, 2020
    risk 0.28cvss 4.3epss 0.01

    Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside the tickets, when system is configured to mask real agent names. This issue affects OTRS; 7.0.21 and prior versions, 8.0.6 and…

  • CVE-2019-13457MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search results to disclose information from their "company" tickets (with the same CustomerID), even when the CustomerDisableCompanyTicketAccess setting is turned on.

  • CVE-2019-10065MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 7.0 through 7.0.6. An attacker who is logged into OTRS as a customer user can use the search result screens to disclose information from internal FAQ articles, a different vulnerability than CVE-2019-9753.

  • CVE-2019-18179MedJan 6, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where…

  • CVE-2019-12248MedJun 17, 2019
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could…

  • CVE-2018-16586MedSep 28, 2018
    risk 0.28cvss 4.3epss 0.01

    In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image or CSS resources.

  • CVE-2018-10198MedJun 6, 2018
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket overview screen to disclose internal article information of their customer tickets.

  • CVE-2023-38058MedJul 24, 2023
    risk 0.27cvss 4.1epss 0.00

    An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

  • CVE-2023-38057MedJul 24, 2023
    risk 0.27cvss 4.1epss 0.00

    An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent.…

  • CVE-2020-1778MedNov 23, 2020
    risk 0.27cvss 4.1epss 0.01

    When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.

  • CVE-2025-24388LowJun 16, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X * …

  • CVE-2022-0473LowFeb 7, 2022
    risk 0.25cvss 3.8epss 0.01

    OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.31…

  • CVE-2026-48191LowJun 1, 2026
    risk 0.23cvss 3.5epss 0.00

    An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them. This issue affects OTRS with STORM…

  • CVE-2026-48190LowJun 1, 2026
    risk 0.23cvss 3.5epss 0.00

    An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected. This issue…

  • CVE-2024-23790LowJan 29, 2024
    risk 0.23cvss 3.5epss 0.00

    Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

  • CVE-2023-5421LowOct 16, 2023
    risk 0.23cvss 3.5epss 0.00

    An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs immediatly after the data is saved.The issue onlyoccurs if the configuration for…

  • CVE-2022-3501LowOct 17, 2022
    risk 0.23cvss 3.5epss 0.00

    Article template contents with sensitive data could be accessed from agents without permissions.

  • CVE-2022-39049LowSep 5, 2022
    risk 0.23cvss 3.5epss 0.01

    An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.

  • CVE-2022-32740LowJun 13, 2022
    risk 0.23cvss 3.5epss 0.01

    A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances.

Page 5 of 8