Vulnerabilities > Otrs > Otrs > 3.2.6

DATE CVE VULNERABILITY TITLE RISK
2014-02-04 CVE-2014-1694 Cross-Site Request Forgery (CSRF) vulnerability in Otrs
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3) CustomerTicketProcess.pm, and (4) CustomerTicketZoom.pm in Kernel/Modules/ in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allow remote attackers to hijack the authentication of arbitrary users for requests that (5) create tickets or (6) send follow-ups to existing tickets.
network
otrs CWE-352
6.8
2014-02-04 CVE-2014-1471 SQL Injection vulnerability in Otrs
SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allows remote attackers to execute arbitrary SQL commands via vectors related to a ticket search URL.
network
low complexity
otrs CWE-89
7.5