Записи otrs
161 опубликованных записей вендора otrs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 68,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')36
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor29
- CWE-20 Improper Input Validation18
- CWE-264 Permissions, Privileges, and Access Controls15
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
161 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2017-16921Proof of concept | In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who iotrs · otrs · CWE-78 | Высокая8,8 | — | 19,9 % | 8 дек. 2017 г. |
39Наблюдать | CVE-2022-4427Эксплойта нет | SQL Injection via OTRS Search APIotrs · otrs · CWE-20 | Критическая9,8 | — | 0,7 % | 19 дек. 2022 г. |
39Наблюдать | CVE-2024-23790Эксплойта нет | Missing file type check in avatar picture uploadotrs · otrs · CWE-20 | Критическая9,8 | — | 0,3 % | 29 янв. 2024 г. |
38Наблюдать | CVE-2016-5843Эксплойта нет | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request Syotrs · faq · CWE-89 | Критическая9,4 | — | 3,2 % | 16 сент. 2016 г. |
36Наблюдать | CVE-2017-16664Эксплойта нет | Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3otrs · otrs · CWE-94 | Высокая8,8 | — | 2,5 % | 21 нояб. 2017 г. |
36Наблюдать | CVE-2017-9324Эксплойта нет | In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is otrs · otrs · CWE-269 | Высокая8,8 | — | 2,4 % | 12 июн. 2017 г. |
36Наблюдать | CVE-2017-17476Эксплойта нет | Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might aotrs · otrs · CWE-200 | Высокая8,8 | — | 2,2 % | 20 дек. 2017 г. |
36Наблюдать | CVE-2017-14635Эксплойта нет | In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage otrs · otrs · CWE-20 | Высокая8,8 | — | 1,9 % | 21 сент. 2017 г. |
36Наблюдать | CVE-2018-14593Эксплойта нет | An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30.otrs · open ticket request system | Высокая8,8 | — | 1,9 % | 3 авг. 2018 г. |
36Наблюдать | CVE-2017-15864Эксплойта нет | In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like otrs · otrs | Высокая8,8 | — | 1,8 % | 16 нояб. 2017 г. |
36Наблюдать | CVE-2026-48188Proof of concept | SQL Injection via MySQL Quote Methodotrs · otrs · CWE-20 | Критическая9,1 | — | 0,5 % | 1 июн. 2026 г. |
36Наблюдать | CVE-2023-5422Эксплойта нет | SSL Certificates are not checked for E-Mail Handlingotrs · otrs · CWE-295 | Критическая9,1 | — | 0,3 % | 16 окт. 2023 г. |
35Наблюдать | CVE-2013-4717Эксплойта нет | Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x beotrs · otrs · CWE-89 | Высокая8,8 | — | 1,3 % | 9 авг. 2021 г. |
35Наблюдать | CVE-2021-36100Эксплойта нет | Authenticated remote code executionotrs · otrs · CWE-78 | Высокая8,8 | — | 1,3 % | 21 мар. 2022 г. |
35Наблюдать | CVE-2022-39051Эксплойта нет | Perl Code execution in Template Toolkitotrs · otrs · CWE-913 | Высокая8,8 | — | 0,8 % | 5 сент. 2022 г. |
35Наблюдать | CVE-2023-38060Эксплойта нет | Host header injection by attachments in web serviceotrs · otrs · CWE-20 | Высокая8,8 | — | 0,7 % | 24 июл. 2023 г. |
32Наблюдать | CVE-2005-3893Proof of concept | Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow reotrs · otrs | Высокая7,5 | — | 7,2 % | 29 нояб. 2005 г. |
32Наблюдать | CVE-2020-1773Эксплойта нет | Session / Password / Password token leakotrs · otrs · CWE-331 | Высокая8,1 | — | 1,5 % | 27 мар. 2020 г. |
32Наблюдать | CVE-2023-2534Эксплойта нет | Information disclouse and DoS via websocket push eventsotrs · otrs · CWE-285 | Высокая8,1 | — | 0,5 % | 8 мая 2023 г. |
32Наблюдать | CVE-2024-43444Эксплойта нет | Passwords are written to Admin Log Moduleotrs ag · otrs · CWE-532 | Высокая8,2 | — | 0,4 % | 26 авг. 2024 г. |
31Наблюдать | CVE-2011-0456Эксплойта нет | webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified veotrs · otrs · CWE-78 | Высокая7,5 | — | 3,0 % | 11 мар. 2011 г. |
31Наблюдать | CVE-2019-18180Эксплойта нет | Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g.otrs · otrs · CWE-835 | Высокая7,5 | — | 2,6 % | 5 дек. 2019 г. |
31Наблюдать | CVE-2014-1471Эксплойта нет | SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x beforeotrs · otrs · CWE-89 | Высокая7,5 | — | 1,8 % | 4 февр. 2014 г. |
31Наблюдать | CVE-2023-1250Эксплойта нет | Code execution through ACL creationotrs · otrs · CWE-20 | Высокая7,8 | — | 0,3 % | 20 мар. 2023 г. |
30Наблюдать | CVE-2018-7567Эксплойта нет | In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are ablotrs · otrs · CWE-434 | Высокая7,2 | — | 5,2 % | 4 мар. 2018 г. |
- CVE-2017-1692141В плане
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who i
ВысокаяCVSS 8,8Proof of conceptEPSS 20 %otrs · otrs8 дек. 2017 г.
- CVE-2022-442739Наблюдать
SQL Injection via OTRS Search API
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %otrs · otrs19 дек. 2022 г.
- CVE-2024-2379039Наблюдать
Missing file type check in avatar picture upload
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %otrs · otrs29 янв. 2024 г.
- CVE-2016-584338Наблюдать
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request Sy
КритическаяCVSS 9,4Эксплойта нетEPSS 3 %otrs · faq16 сент. 2016 г.
- CVE-2017-1666436Наблюдать
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %otrs · otrs21 нояб. 2017 г.
- CVE-2017-932436Наблюдать
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %otrs · otrs12 июн. 2017 г.
- CVE-2017-1747636Наблюдать
Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %otrs · otrs20 дек. 2017 г.
- CVE-2017-1463536Наблюдать
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %otrs · otrs21 сент. 2017 г.
- CVE-2018-1459336Наблюдать
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %otrs · open ticket request system3 авг. 2018 г.
- CVE-2017-1586436Наблюдать
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %otrs · otrs16 нояб. 2017 г.
- CVE-2026-4818836Наблюдать
SQL Injection via MySQL Quote Method
КритическаяCVSS 9,1Proof of conceptEPSS 0 %otrs · otrs1 июн. 2026 г.
- CVE-2023-542236Наблюдать
SSL Certificates are not checked for E-Mail Handling
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %otrs · otrs16 окт. 2023 г.
- CVE-2013-471735Наблюдать
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x be
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %otrs · otrs9 авг. 2021 г.
- CVE-2021-3610035Наблюдать
Authenticated remote code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %otrs · otrs21 мар. 2022 г.
- CVE-2022-3905135Наблюдать
Perl Code execution in Template Toolkit
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %otrs · otrs5 сент. 2022 г.
- CVE-2023-3806035Наблюдать
Host header injection by attachments in web service
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %otrs · otrs24 июл. 2023 г.
- CVE-2005-389332Наблюдать
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow re
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %otrs · otrs29 нояб. 2005 г.
- CVE-2020-177332Наблюдать
Session / Password / Password token leak
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %otrs · otrs27 мар. 2020 г.
- CVE-2023-253432Наблюдать
Information disclouse and DoS via websocket push events
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %otrs · otrs8 мая 2023 г.
- CVE-2024-4344432Наблюдать
Passwords are written to Admin Log Module
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %otrs ag · otrs26 авг. 2024 г.
- CVE-2011-045631Наблюдать
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified ve
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %otrs · otrs11 мар. 2011 г.
- CVE-2019-1818031Наблюдать
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %otrs · otrs5 дек. 2019 г.
- CVE-2014-147131Наблюдать
SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %otrs · otrs4 февр. 2014 г.
- CVE-2023-125031Наблюдать
Code execution through ACL creation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %otrs · otrs20 мар. 2023 г.
- CVE-2018-756730Наблюдать
In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are abl
ВысокаяCVSS 7,2Эксплойта нетEPSS 5 %otrs · otrs4 мар. 2018 г.