Otrs

Otrs

138 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 10.03.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:56

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search results to disclose information from their "company" tickets (with the same CustomerID), even when the CustomerDisableCompanyTicketAc...

  • EPSS 0.2%
  • Veröffentlicht 10.03.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:19

An issue was discovered in Open Ticket Request System (OTRS) 7.0 through 7.0.6. An attacker who is logged into OTRS as a customer user can use the search result screens to disclose information from internal FAQ articles, a different vulnerability tha...

  • EPSS 0.48%
  • Veröffentlicht 21.02.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 01:53:51

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets,...

  • EPSS 1.93%
  • Veröffentlicht 21.02.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 01:54:51

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted t...

  • EPSS 0.31%
  • Veröffentlicht 07.02.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 05:11:20

The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

  • EPSS 0.78%
  • Veröffentlicht 10.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:20

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Comm...

  • EPSS 0.8%
  • Veröffentlicht 10.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:20

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue ...

  • EPSS 0.87%
  • Veröffentlicht 10.01.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:11:20

An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5....

  • EPSS 0.52%
  • Veröffentlicht 06.01.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:32:46

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, ...

  • EPSS 1.33%
  • Veröffentlicht 05.12.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:46

Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects...