VYPR
Vendor

OTRS

OTRS is a service management suite. The suite contains an agent portal, admin dashboard and customer portal. In the agent portal, teams process tickets and requests from customers. There are various ways in which this information, as well as customer and related data can be viewed. As the name implies, the admin dashboard allows system administrators to manage the system: Options are many, but include roles and groups, process automation, channel integration, and CMDB/database options.

Founded 2001
Products
34
CVEs
170
Across products
275
Status
Private

Products

34
View all 34 products →

Recent CVEs

170
View all 170 CVEs →
  • CVE-2017-16921HigDec 8, 2017
    risk 0.62cvss 8.8epss 0.20

    In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of…

  • CVE-2016-5843CriSep 17, 2016
    risk 0.61cvss 9.4epss 0.03

    Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.

  • CVE-2026-48188CriJun 1, 2026
    risk 0.59cvss 9.1epss 0.01

    An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the…

  • CVE-2023-5422HigOct 16, 2023
    risk 0.57cvss 8.7epss 0.00

    The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate …

  • CVE-2013-4717HigAug 9, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to…

  • CVE-2018-14593HigAug 4, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

  • CVE-2017-17476HigDec 20, 2017
    risk 0.57cvss 8.8epss 0.02

    Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.

  • CVE-2017-16664HigNov 21, 2017
    risk 0.57cvss 8.8epss 0.02

    Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.

  • CVE-2017-15864HigNov 16, 2017
    risk 0.57cvss 8.8epss 0.02

    In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.

  • CVE-2017-14635HigSep 21, 2017
    risk 0.57cvss 8.8epss 0.02

    In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.

  • CVE-2017-9324HigJun 12, 2017
    risk 0.57cvss 8.8epss 0.02

    In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read…

  • CVE-2024-43444HigAug 26, 2024
    risk 0.53cvss 8.2epss 0.00

    Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: * OTRS from 7.0.X through…

  • CVE-2023-6254HigNov 27, 2023
    risk 0.53cvss 8.1epss 0.01

    A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.

  • CVE-2023-2534HigMay 8, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by…

  • CVE-2022-39052HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system

  • CVE-2021-21441HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This…

  • CVE-2023-1250HigMar 20, 2023
    risk 0.48cvss 7.4epss 0.00

    Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This…

  • CVE-2020-1773HigMar 27, 2020
    risk 0.48cvss 7.3epss 0.01

    An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects…

  • CVE-2023-38056HigJul 24, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from…

  • CVE-2018-7567HigMar 4, 2018
    risk 0.47cvss 7.2epss 0.05

    In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a…