CVE-2023-6254
- EPSS 0.18%
- Veröffentlicht 27.11.2023 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:28
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.
CVE-2023-5422
- EPSS 0.19%
- Veröffentlicht 16.10.2023 09:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:44
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured...
CVE-2023-5421
- EPSS 0.29%
- Veröffentlicht 16.10.2023 09:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:44
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs immediatly after the data is saved.The issue onlyoccurs if the configurat...
CVE-2023-38059
- EPSS 0.28%
- Veröffentlicht 16.10.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:12:46
The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37;...
CVE-2023-38058
- EPSS 0.12%
- Veröffentlicht 24.07.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:12:46
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.
CVE-2023-38060
- EPSS 0.19%
- Veröffentlicht 24.07.2023 09:15:10
- Zuletzt bearbeitet 13.02.2025 17:16:47
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the C...
CVE-2023-38056
- EPSS 0.38%
- Veröffentlicht 24.07.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:12:45
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: fro...
CVE-2023-2534
- EPSS 0.11%
- Veröffentlicht 08.05.2023 08:15:43
- Zuletzt bearbeitet 21.11.2024 07:58:47
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e....
CVE-2018-17883
- EPSS 0.51%
- Veröffentlicht 16.04.2023 00:15:07
- Zuletzt bearbeitet 06.02.2025 17:15:10
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of Java...
CVE-2023-1250
- EPSS 0.05%
- Veröffentlicht 20.03.2023 09:15:12
- Zuletzt bearbeitet 21.11.2024 07:38:45
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated c...