Vulnerabilities > Otrs

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2019-9892 XML Injection (aka Blind XPath Injection) vulnerability in multiple products
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6.
network
low complexity
otrs debian CWE-91
6.5
2019-05-22 CVE-2019-10067 Cross-site Scripting vulnerability in Otrs
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.35 and 6.0.x through 6.0.17.
network
low complexity
otrs CWE-79
5.4
2019-05-22 CVE-2019-10066 Cross-site Scripting vulnerability in Otrs
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5.0.x through 5.0.12.
network
low complexity
otrs CWE-79
5.4
2019-03-13 CVE-2019-9752 Cross-site Scripting vulnerability in multiple products
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4.
network
low complexity
otrs opensuse CWE-79
5.4
2019-03-13 CVE-2019-9751 Cross-site Scripting vulnerability in Otrs
An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5.
network
low complexity
otrs CWE-79
4.8
2019-03-13 CVE-2018-20800 Improper Input Validation vulnerability in Otrs 5.0.31/6.0.13
An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13.
network
low complexity
otrs CWE-20
6.5
2018-11-11 CVE-2018-19143 Forced Browsing vulnerability in multiple products
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
network
low complexity
otrs debian CWE-425
6.5
2018-11-11 CVE-2018-19142 Cross-site Scripting vulnerability in Otrs Open Ticket Request System
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
network
low complexity
otrs CWE-79
4.8
2018-11-11 CVE-2018-19141 Cross-site Scripting vulnerability in multiple products
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
network
low complexity
otrs debian CWE-79
4.8
2018-09-28 CVE-2018-16587 Improper Input Validation vulnerability in multiple products
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system.
network
low complexity
otrs debian CWE-20
6.5