CVE-2025-24391
- EPSS 0.04%
- Veröffentlicht 14.07.2025 08:15:58
- Zuletzt bearbeitet 15.07.2025 13:14:24
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This...
CVE-2025-24387
- EPSS 0.03%
- Veröffentlicht 10.03.2025 09:28:31
- Zuletzt bearbeitet 24.03.2025 14:11:20
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, pe...
CVE-2025-24390
- EPSS 0.03%
- Veröffentlicht 27.01.2025 06:15:24
- Zuletzt bearbeitet 27.01.2025 06:15:24
A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OT...
CVE-2024-43444
- EPSS 0.15%
- Veröffentlicht 26.08.2024 09:15:04
- Zuletzt bearbeitet 26.08.2024 12:47:20
Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: * ...
CVE-2024-23794
- EPSS 0.11%
- Veröffentlicht 15.07.2024 08:15:02
- Zuletzt bearbeitet 21.11.2024 08:58:25
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instanc...
CVE-2024-6540
- EPSS 0.33%
- Veröffentlicht 15.07.2024 08:15:02
- Zuletzt bearbeitet 21.11.2024 09:49:50
Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem onl...
CVE-2024-23793
- EPSS 0.24%
- Veröffentlicht 06.06.2024 19:15:52
- Zuletzt bearbeitet 21.11.2024 08:58:25
The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially ...
CVE-2024-23790
- EPSS 0.19%
- Veröffentlicht 29.01.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:58:25
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023...
CVE-2024-23791
- EPSS 0.14%
- Veröffentlicht 29.01.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:58:25
Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
CVE-2024-23792
- EPSS 0.1%
- Veröffentlicht 29.01.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:58:25
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user c...