Otrs

Otrs

138 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.95%
  • Veröffentlicht 23.08.2012 10:32:14
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow r...

  • EPSS 0.43%
  • Veröffentlicht 29.08.2011 15:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in Kernel/Modules/AdminPackageManager.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.x before 2.4.11 and 3.x before 3.0.10 allows remote authenticated administrators to read arbitrary files via unknown vectors.

  • EPSS 0.74%
  • Veröffentlicht 19.07.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or...

  • EPSS 0.45%
  • Veröffentlicht 18.04.2011 18:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.4.x before 2.4.10 and 3.x before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.21%
  • Veröffentlicht 18.03.2011 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.

  • EPSS 0.04%
  • Veröffentlicht 18.03.2011 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations, related to ...

  • EPSS 0.2%
  • Veröffentlicht 18.03.2011 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictio...

  • EPSS 0.31%
  • Veröffentlicht 18.03.2011 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages ...

  • EPSS 0.2%
  • Veröffentlicht 18.03.2011 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.8 allows remote authenticated users to bypass intended access restrictions and access tickets of arbitrary customers via unspecified vectors.

  • EPSS 0.59%
  • Veröffentlicht 18.03.2011 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Request System (OTRS) before 2.2.7 does not properly handle e-mail messages containing malformed UTF-8 characters, which allows remote attackers to cause a denial of service (e-mail ret...