Show filters
145 Total Results
Displaying 21-30 of 145
Sort by:
Attacker Value
Unknown

CVE-2023-38056

Disclosure Date: July 24, 2023 (last updated October 08, 2023)
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Attacker Value
Unknown

CVE-2023-2534

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.
Attacker Value
Unknown

CVE-2018-17883

Disclosure Date: April 16, 2023 (last updated October 08, 2023)
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.
Attacker Value
Unknown

CVE-2023-1250

Disclosure Date: March 20, 2023 (last updated November 08, 2023)
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Attacker Value
Unknown

CVE-2023-1248

Disclosure Date: March 20, 2023 (last updated November 08, 2023)
Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Attacker Value
Unknown

CVE-2022-4427

Disclosure Date: December 19, 2022 (last updated February 14, 2025)
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Attacker Value
Unknown

CVE-2022-39052

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
Attacker Value
Unknown

CVE-2022-3501

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Article template contents with sensitive data could be accessed from agents without permissions.
Attacker Value
Unknown

CVE-2022-39050

Disclosure Date: September 05, 2022 (last updated October 08, 2023)
An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap
Attacker Value
Unknown

CVE-2022-39051

Disclosure Date: September 05, 2022 (last updated October 08, 2023)
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package