Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Otrs HIGH 8.8
CVE-2021-36100

Specially crafted string in OTRS system configuration can allow the execution of any system command.

Fix: 7.0.19 / 7.0.28+
Fix from $1,950 2022-03-21
Otrs MEDIUM 5.4
CVE-2022-0475

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package…

Fix: after 8.0.19
Fix from $1,600 2022-03-21
Otrs MEDIUM 5.4
CVE-2021-36094

It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edit…

Fix: 7.0.29+
Fix from $1,600 2021-09-06
Otrs MEDIUM 5.3
CVE-2021-36093

It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Co…

Fix: 7.0.29 / 8.0.16+
Fix from $1,600 2021-09-06
Otrs MEDIUM 5.3
CVE-2021-36095

Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition…

Fix: 7.0.29+
Fix from $1,600 2021-09-06
Otrs HIGH 8.8
CVE-2013-4717

Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.…

Fix: after 3.2.8
Fix from $1,950 2021-08-09
Otrs MEDIUM 5.4
CVE-2013-4718

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 al…

Fix: after 3.2.8
Fix from $1,600 2021-08-09
Otrs MEDIUM 6.5
CVE-2021-21440

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edi…

Fix: after 8.0.14
Fix from $1,600 2021-07-26
Otrs MEDIUM 6.1
CVE-2021-36092

It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS))…

Fix: 7.0.28 / 8.0.15+
Fix from $1,600 2021-07-26
Time Accounting MEDIUM 5.4
CVE-2021-21442

In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. Thi…

Fix: 7.0.20+
Fix from $1,600 2021-07-26
Otrs HIGH 7.5
CVE-2021-21441

There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview s…

Fix: after 7.0.26
Fix from $1,950 2021-06-16
Otrs MEDIUM 6.5
CVE-2021-21439

DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of ser…

Fix: 7.0.27 / 8.0.14+
Fix from $1,600 2021-06-14
Otrs MEDIUM 6.5
CVE-2021-21435

Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG…

Fix: after 8.0.10
Fix from $1,600 2021-02-08
Otrs MEDIUM 5.3
CVE-2020-1777

Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside…

Fix: after 8.0.6
Fix from $1,600 2020-10-15
Otrs HIGH 8.1
CVE-2020-1773

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may…

Fix: after 7.0.15
Fix from $1,950 2020-03-27
Otrs MEDIUM 5.4
CVE-2020-1771

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript…

Fix: after 7.0.15
Fix from $1,600 2020-03-27
Otrs MEDIUM 5.4
CVE-2019-16375

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.2…

Fix: after 7.0.11
Fix from $1,600 2020-03-19
Otrs MEDIUM 6.5
CVE-2013-3551

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS IT…

Fix: 3.0.8 / 3.0.20+
Fix from $1,600 2020-02-21
Otrs MEDIUM 6.5
CVE-2013-4088

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not p…

Fix: 3.0.21 / 3.1.17+
Fix from $1,600 2020-02-21
Faq MEDIUM 6.1
CVE-2013-2637

A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workord…

Fix: 2.0.8 / 2.1.4+
Fix from $1,600 2020-02-12
Otrs MEDIUM 5.4
CVE-2020-1768

The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdle…

Fix: after 7.0.14
Fix from $1,600 2020-02-07
Otrs HIGH 7.5
CVE-2019-18180

Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTR…

Fix: 5.0.39 / 6.0.24+
Fix from $1,950 2019-12-05
Otrs MEDIUM 5.4
CVE-2019-10066

An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5…

Fix: after 7.0.6
Fix from $1,600 2019-05-22
Otrs MEDIUM 5.4
CVE-2019-10067

An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.35 and 6.0.x through 6.0.17. A…

Fix: after 7.0.6
Fix from $1,600 2019-05-22
Otrs MEDIUM 6.5
CVE-2018-20800

An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only ma…

Patch available
Fix from $1,600 2019-03-13
Otrs MEDIUM 5.4
CVE-2019-9752

An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged in…

Fix: 5.0.34 / 6.0.16+
Fix from $1,600 2019-03-13
Otrs HIGH 7.2
CVE-2018-7567EPSS 5%

In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to expl…

Fix: after 5.0.23
Fix from $1,950 2018-03-04
Otrs HIGH 8.8
CVE-2017-14635

In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistic…

Mitigation only
Fix from $1,950 2017-09-21
Otrs MEDIUM 6.1
CVE-2017-9299

Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks.…

No fix yet
Fix from $1,600 2017-05-29
Otrs MEDIUM 6.1
CVE-2016-9139

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allow…

Mitigation only
Fix from $1,600 2017-02-17