Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
otrs open ticket request system vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2018-19142
Open Ticket Request System (OTRS) 6.0.x prior to 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
Otrs Open Ticket Request System
3.5
CVSSv2
CVE-2018-19141
Open Ticket Request System (OTRS) 4.0.x prior to 4.0.33 and 5.0.x prior to 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
Otrs Open Ticket Request System
Debian Debian Linux 8.0
5.5
CVSSv2
CVE-2018-19143
Open Ticket Request System (OTRS) 4.0.x prior to 4.0.33, 5.0.x prior to 5.0.31, and 6.0.x prior to 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
Otrs Open Ticket Request System
Debian Debian Linux 8.0
5.8
CVSSv2
CVE-2018-16587
In Open Ticket Request System (OTRS) 4.0.x prior to 4.0.32, 5.0.x prior to 5.0.30, and 6.0.x prior to 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server use...
Otrs Open Ticket Request System
Debian Debian Linux 8.0
Debian Debian Linux 9.0
4.3
CVSSv2
CVE-2018-16586
In Open Ticket Request System (OTRS) 4.0.x prior to 4.0.32, 5.0.x prior to 5.0.30, and 6.0.x prior to 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image or CSS resources.
Otrs Open Ticket Request System
Debian Debian Linux 8.0
Debian Debian Linux 9.0
6.5
CVSSv2
CVE-2018-14593
An issue exists in Open Ticket Request System (OTRS) 6.0.x up to and including 6.0.9, 5.0.x up to and including 5.0.28, and 4.0.x up to and including 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.
Otrs Open Ticket Request System
Debian Debian Linux 8.0
Debian Debian Linux 9.0
2.6
CVSSv2
CVE-2012-4600
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x prior to 2.4.14, 3.0.x prior to 3.0.16, and 3.1.x prior to 3.1.10, when Firefox or Opera is used, allows remote malicious users to inject arbitrary web script or HTML via an e-mail messa...
Otrs Otrs 2.4.0
Otrs Otrs 2.4.1
Otrs Otrs 2.4.10
Otrs Otrs 2.4.5
Otrs Otrs 2.4.13
Otrs Otrs 2.4.12
Otrs Otrs 2.4.6
Otrs Otrs 2.4.9
Otrs Otrs 2.4.3
Otrs Otrs 2.4.11
Otrs Otrs 2.4.4
Otrs Otrs 2.4.2
Otrs Otrs 2.4.8
Otrs Otrs 2.4.7
Otrs Otrs 3.0.12
Otrs Otrs Itsm 3.0.4
Otrs Otrs Itsm 3.0.2
Otrs Otrs 3.0.10
Otrs Otrs 3.0.2
Otrs Otrs 3.0.15
Otrs Otrs Itsm 3.0.5
Otrs Otrs 3.0.0
2 EDB exploits
4.3
CVSSv2
CVE-2012-2582
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x prior to 2.4.13, 3.0.x prior to 3.0.15, and 3.1.x prior to 3.1.9, and OTRS ITSM 2.1.x prior to 2.1.5, 3.0.x prior to 3.0.6, and 3.1.x prior to 3.1.6, allow remote malicious us...
Otrs Otrs 2.4.0
Otrs Otrs 2.4.9
Otrs Otrs 2.4.4
Otrs Otrs 2.4.3
Otrs Otrs 2.4.2
Otrs Otrs 2.4.10
Otrs Otrs 2.4.6
Otrs Otrs 2.4.5
Otrs Otrs 2.4.11
Otrs Otrs 2.4.1
Otrs Otrs 2.4.8
Otrs Otrs 2.4.7
Otrs Otrs 2.4.12
Otrs Otrs 3.0.0
Otrs Otrs 3.0.3
Otrs Otrs 3.0.2
Otrs Otrs 3.0.11
Otrs Otrs 3.0.12
Otrs Otrs 3.0.4
Otrs Otrs 3.0.7
Otrs Otrs 3.0.6
Otrs Otrs 3.0.10
1 EDB exploit
2.1
CVSSv2
CVE-2009-5056
Open Ticket Request System (OTRS) prior to 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket f...
Otrs Otrs 2.1.1
Otrs Otrs 2.2.4
Otrs Otrs 2.1.5
Otrs Otrs 2.3.2
Otrs Otrs 2.2.1
Otrs Otrs 2.2.2
Otrs Otrs 2.0.3
Otrs Otrs 2.0.4
Otrs Otrs 0.5
Otrs Otrs 1.0
Otrs Otrs 2.2.9
Otrs Otrs 2.2.5
Otrs Otrs 2.1.7
Otrs Otrs 2.0.0
Otrs Otrs 1.0.2
Otrs Otrs 1.1.0
Otrs Otrs 1.2.3
Otrs Otrs 1.3.0
Otrs Otrs 2.3.5
Otrs Otrs
Otrs Otrs 2.1.0
Otrs Otrs 2.1.9
3.5
CVSSv2
CVE-2010-4760
Open Ticket Request System (OTRS) prior to 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.
Otrs Otrs 2.1.1
Otrs Otrs 2.2.6
Otrs Otrs 2.2.4
Otrs Otrs 2.2.8
Otrs Otrs 2.2.0
Otrs Otrs 1.3.2
Otrs Otrs 2.2.1
Otrs Otrs 2.0.0
Otrs Otrs 0.5
Otrs Otrs 1.0
Otrs Otrs 2.1.7
Otrs Otrs 1.3.1
Otrs Otrs 1.2.1
Otrs Otrs 1.2.2
Otrs Otrs 1.2.3
Otrs Otrs 1.3.0
Otrs Otrs 2.4.4
Otrs Otrs 2.4.5
Otrs Otrs 2.3.5
Otrs Otrs 2.4.6
Otrs Otrs 2.1.5
Otrs Otrs 2.3.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »