Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2013-4717
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm.
0
Attacker Value
Unknown
CVE-2013-4718
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.
0
Attacker Value
Unknown
CVE-2021-28142
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
0
Attacker Value
Unknown
CVE-2021-21437
Disclosure Date: March 22, 2021 (last updated February 22, 2025)
Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions
0
Attacker Value
Unknown
CVE-2020-35775
Disclosure Date: February 15, 2021 (last updated February 22, 2025)
CITSmart before 9.1.2.23 allows LDAP Injection.
0
Attacker Value
Unknown
CVE-2013-3551
Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
0
Attacker Value
Unknown
CVE-2013-2637
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
0
Attacker Value
Unknown
CVE-2013-2625
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
0
Attacker Value
Unknown
CVE-2013-2594
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
0
Attacker Value
Unknown
CVE-2012-4600
Disclosure Date: August 31, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.
0