Vulnerabilities > Otrs
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-06 | CVE-2021-36094 | Cross-site Scripting vulnerability in Otrs It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. | 3.5 |
2021-09-06 | CVE-2021-36095 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Otrs Malicious attacker is able to find out valid user logins by using the "lost password" feature. | 5.0 |
2021-08-09 | CVE-2013-4717 | SQL Injection vulnerability in Otrs Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm. | 6.5 |
2021-08-09 | CVE-2013-4718 | Cross-site Scripting vulnerability in Otrs Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search. | 3.5 |
2021-07-26 | CVE-2021-21440 | Unspecified vulnerability in Otrs Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. | 6.5 |
2021-07-26 | CVE-2021-21442 | Cross-site Scripting vulnerability in Otrs Time Accounting 7.0.0/7.0.19 In the project create screen it's possible to inject malicious JS code to the certain fields. | 4.3 |
2021-07-26 | CVE-2021-21443 | Unspecified vulnerability in Otrs Agents are able to list customer user emails without required permissions in the bulk action screen. | 4.3 |
2021-07-26 | CVE-2021-36091 | Incorrect Authorization vulnerability in Otrs Agents are able to list appointments in the calendars without required permissions. | 4.3 |
2021-07-26 | CVE-2021-36092 | Cross-site Scripting vulnerability in Otrs It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. | 4.3 |
2021-06-16 | CVE-2021-21441 | Cross-site Scripting vulnerability in Otrs There is a XSS vulnerability in the ticket overview screens. | 7.5 |