İçeriğe atla
Noroxi

otrs kayıtları

otrs üreticisine ait 161 yayımlanmış kayıt.

Tüm kayıtlar

161 kayıt
  • CVE-2017-16921
    41Planlayın

    In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who i

    YüksekCVSS 8,8Kavram kanıtıEPSS %20

    otrs · otrs8 Ara 2017

  • CVE-2022-4427
    39İzleyin

    SQL Injection via OTRS Search API

    KritikCVSS 9,8İstismar yokEPSS %1

    otrs · otrs19 Ara 2022

  • CVE-2024-23790
    39İzleyin

    Missing file type check in avatar picture upload

    KritikCVSS 9,8İstismar yokEPSS %0

    otrs · otrs29 Oca 2024

  • CVE-2016-5843
    38İzleyin

    Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request Sy

    KritikCVSS 9,4İstismar yokEPSS %3

    otrs · faq16 Eyl 2016

  • CVE-2017-16664
    36İzleyin

    Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3

    YüksekCVSS 8,8İstismar yokEPSS %2

    otrs · otrs21 Kas 2017

  • CVE-2017-9324
    36İzleyin

    In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is

    YüksekCVSS 8,8İstismar yokEPSS %2

    otrs · otrs12 Haz 2017

  • CVE-2017-17476
    36İzleyin

    Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might a

    YüksekCVSS 8,8İstismar yokEPSS %2

    otrs · otrs20 Ara 2017

  • CVE-2017-14635
    36İzleyin

    In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage

    YüksekCVSS 8,8İstismar yokEPSS %2

    otrs · otrs21 Eyl 2017

  • CVE-2018-14593
    36İzleyin

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30.

    YüksekCVSS 8,8İstismar yokEPSS %2

    otrs · open ticket request system3 Ağu 2018

  • CVE-2017-15864
    36İzleyin

    In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like

    YüksekCVSS 8,8İstismar yokEPSS %2

    otrs · otrs16 Kas 2017

  • CVE-2026-48188
    36İzleyin

    SQL Injection via MySQL Quote Method

    KritikCVSS 9,1Kavram kanıtıEPSS %0

    otrs · otrs1 Haz 2026

  • CVE-2023-5422
    36İzleyin

    SSL Certificates are not checked for E-Mail Handling

    KritikCVSS 9,1İstismar yokEPSS %0

    otrs · otrs16 Eki 2023

  • CVE-2013-4717
    35İzleyin

    Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x be

    YüksekCVSS 8,8İstismar yokEPSS %1

    otrs · otrs9 Ağu 2021

  • CVE-2021-36100
    35İzleyin

    Authenticated remote code execution

    YüksekCVSS 8,8İstismar yokEPSS %1

    otrs · otrs21 Mar 2022

  • CVE-2022-39051
    35İzleyin

    Perl Code execution in Template Toolkit

    YüksekCVSS 8,8İstismar yokEPSS %1

    otrs · otrs5 Eyl 2022

  • CVE-2023-38060
    35İzleyin

    Host header injection by attachments in web service

    YüksekCVSS 8,8İstismar yokEPSS %1

    otrs · otrs24 Tem 2023

  • CVE-2005-3893
    32İzleyin

    Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow re

    YüksekCVSS 7,5Kavram kanıtıEPSS %7

    otrs · otrs29 Kas 2005

  • CVE-2020-1773
    32İzleyin

    Session / Password / Password token leak

    YüksekCVSS 8,1İstismar yokEPSS %1

    otrs · otrs27 Mar 2020

  • CVE-2023-2534
    32İzleyin

    Information disclouse and DoS via websocket push events

    YüksekCVSS 8,1İstismar yokEPSS %1

    otrs · otrs8 May 2023

  • CVE-2024-43444
    32İzleyin

    Passwords are written to Admin Log Module

    YüksekCVSS 8,2İstismar yokEPSS %0

    otrs ag · otrs26 Ağu 2024

  • CVE-2011-0456
    31İzleyin

    webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified ve

    YüksekCVSS 7,5İstismar yokEPSS %3

    otrs · otrs11 Mar 2011

  • CVE-2019-18180
    31İzleyin

    Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g.

    YüksekCVSS 7,5İstismar yokEPSS %3

    otrs · otrs5 Ara 2019

  • CVE-2014-1471
    31İzleyin

    SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before

    YüksekCVSS 7,5İstismar yokEPSS %2

    otrs · otrs4 Şub 2014

  • CVE-2023-1250
    31İzleyin

    Code execution through ACL creation

    YüksekCVSS 7,8İstismar yokEPSS %0

    otrs · otrs20 Mar 2023

  • CVE-2018-7567
    30İzleyin

    In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are abl

    YüksekCVSS 7,2İstismar yokEPSS %5

    otrs · otrs4 Mar 2018