Show filters
145 Total Results
Displaying 81-90 of 145
Sort by:
Attacker Value
Unknown
CVE-2019-12497
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.
0
Attacker Value
Unknown
CVE-2019-9753
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an agent or a customer user can use the search result screens to disclose information from invalid system entities. Following is the list of affected entities: Custom Pages, FAQ Articles, Service Catalogue Items, ITSM Configuration Items.
0
Attacker Value
Unknown
CVE-2019-10066
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5.0.x through 5.0.12. An attacker who is logged into OTRS as an agent with appropriate permissions may create a carefully crafted calendar appointment in order to cause execution of JavaScript in the context of OTRS.
0
Attacker Value
Unknown
CVE-2019-10067
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.35 and 6.0.x through 6.0.17. An attacker who is logged into OTRS as an agent user with appropriate permissions may manipulate the URL to cause execution of JavaScript in the context of OTRS.
0
Attacker Value
Unknown
CVE-2019-9892
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbitrary files on the OTRS filesystem.
0
Attacker Value
Unknown
CVE-2019-18179
Disclosure Date: May 03, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
0
Attacker Value
Unknown
CVE-2018-20800
Disclosure Date: March 13, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table.
0
Attacker Value
Unknown
CVE-2019-9751
Disclosure Date: March 13, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to Kernel/Output/Template/Document.pm.
0
Attacker Value
Unknown
CVE-2019-9752
Disclosure Date: March 13, 2019 (last updated November 27, 2024)
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Modules/PictureUpload.pm.
0
Attacker Value
Unknown
CVE-2018-10198
Disclosure Date: June 06, 2018 (last updated November 26, 2024)
An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket overview screen to disclose internal article information of their customer tickets.
0