📦 Otrs

by Otrs

🔍 What is Otrs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-6254

HIGH CVSS 8.1 Nov 27, 2023

This vulnerability in OTRS AgentInterface and ExternalInterface allows attackers to read plain text passwords that are inadvertently sent back to clients in server responses. It affects OTRS installat...

CVE-2023-5422

HIGH CVSS 8.7 Oct 16, 2023

This vulnerability in OTRS and OTRS Community Edition allows attackers to intercept email communications by using invalid or expired SSL/TLS certificates. The software fails to properly verify certifi...

CVE-2023-38056

HIGH CVSS 7.2 Jul 24, 2023

This vulnerability allows authenticated OTRS administrators to execute arbitrary commands on the server through improper input sanitization in the System Configuration module. It affects OTRS versions...

CVE-2023-2534

HIGH CVSS 7.6 May 8, 2023

An improper authorization vulnerability in OTRS 8's Websocket API backend allows authenticated agents to track user behavior and gain live system insights. Attackers can correlate user IDs with real n...

CVE-2023-1250

HIGH CVSS 7.4 Mar 20, 2023

This vulnerability allows local attackers to execute arbitrary code on OTRS systems by injecting malicious code into ACL module comments or names during creation or import. It affects OTRS AG OTRS and...

CVE-2013-4717

HIGH CVSS 8.8 Aug 9, 2021

Multiple SQL injection vulnerabilities in OTRS Help Desk allow authenticated users to execute arbitrary SQL commands. This affects OTRS versions 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x bef...

CVE-2025-24387

MEDIUM CVSS 4.8 Mar 10, 2025

This vulnerability in OTRS Application Server allows session hijacking due to insecure cookie settings in HTTPS sessions. Attackers can steal authentication cookies via cross-site requests, potentiall...

CVE-2024-23794

MEDIUM CVSS 5.2 Jul 15, 2024

An incorrect privilege assignment vulnerability in OTRS allows agents with read-only permissions to gain full access to tickets in rare configurations. This privilege escalation occurs when an admin h...