Перейти к содержимому
Noroxi

Записи otrs

161 опубликованных записей вендора otrs.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
68,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

161 записей
  • CVE-2017-16921
    41В плане

    In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who i

    ВысокаяCVSS 8,8Proof of conceptEPSS 20 %

    otrs · otrs8 дек. 2017 г.

  • CVE-2022-4427
    39Наблюдать

    SQL Injection via OTRS Search API

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    otrs · otrs19 дек. 2022 г.

  • CVE-2024-23790
    39Наблюдать

    Missing file type check in avatar picture upload

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    otrs · otrs29 янв. 2024 г.

  • CVE-2016-5843
    38Наблюдать

    Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request Sy

    КритическаяCVSS 9,4Эксплойта нетEPSS 3 %

    otrs · faq16 сент. 2016 г.

  • CVE-2017-16664
    36Наблюдать

    Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    otrs · otrs21 нояб. 2017 г.

  • CVE-2017-9324
    36Наблюдать

    In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    otrs · otrs12 июн. 2017 г.

  • CVE-2017-17476
    36Наблюдать

    Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    otrs · otrs20 дек. 2017 г.

  • CVE-2017-14635
    36Наблюдать

    In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    otrs · otrs21 сент. 2017 г.

  • CVE-2018-14593
    36Наблюдать

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    otrs · open ticket request system3 авг. 2018 г.

  • CVE-2017-15864
    36Наблюдать

    In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    otrs · otrs16 нояб. 2017 г.

  • CVE-2026-48188
    36Наблюдать

    SQL Injection via MySQL Quote Method

    КритическаяCVSS 9,1Proof of conceptEPSS 0 %

    otrs · otrs1 июн. 2026 г.

  • CVE-2023-5422
    36Наблюдать

    SSL Certificates are not checked for E-Mail Handling

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    otrs · otrs16 окт. 2023 г.

  • CVE-2013-4717
    35Наблюдать

    Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x be

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    otrs · otrs9 авг. 2021 г.

  • CVE-2021-36100
    35Наблюдать

    Authenticated remote code execution

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    otrs · otrs21 мар. 2022 г.

  • CVE-2022-39051
    35Наблюдать

    Perl Code execution in Template Toolkit

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    otrs · otrs5 сент. 2022 г.

  • CVE-2023-38060
    35Наблюдать

    Host header injection by attachments in web service

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    otrs · otrs24 июл. 2023 г.

  • CVE-2005-3893
    32Наблюдать

    Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow re

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    otrs · otrs29 нояб. 2005 г.

  • CVE-2020-1773
    32Наблюдать

    Session / Password / Password token leak

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    otrs · otrs27 мар. 2020 г.

  • CVE-2023-2534
    32Наблюдать

    Information disclouse and DoS via websocket push events

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    otrs · otrs8 мая 2023 г.

  • CVE-2024-43444
    32Наблюдать

    Passwords are written to Admin Log Module

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    otrs ag · otrs26 авг. 2024 г.

  • CVE-2011-0456
    31Наблюдать

    webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified ve

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    otrs · otrs11 мар. 2011 г.

  • CVE-2019-18180
    31Наблюдать

    Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    otrs · otrs5 дек. 2019 г.

  • CVE-2014-1471
    31Наблюдать

    SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    otrs · otrs4 февр. 2014 г.

  • CVE-2023-1250
    31Наблюдать

    Code execution through ACL creation

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    otrs · otrs20 мар. 2023 г.

  • CVE-2018-7567
    30Наблюдать

    In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are abl

    ВысокаяCVSS 7,2Эксплойта нетEPSS 5 %

    otrs · otrs4 мар. 2018 г.