ZeroHour

Vulnerabilities

107 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-48188
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode. This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X * (OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

NVD description · AI analysis pending
9.1
group max
<1%
  • otrs otrs
CVE-2026-48210
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue affects OTRS 2026.3.1

NVD description · AI analysis pending
5.7<1%
  • otrs otrs
CVE-2025-24387
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions.

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.x

NVD description · AI analysis pending
6.5<1%
  • otrs otrs
CVE-2024-23794
+1 in the same advisory: …6540
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation.

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has previously enabled the setting 'RequiredLock' of 'AgentFrontend::Ticket::InlineEditing::Property###Watch' in the system configuration.This issue affects OTRS: * 8.0.X * 2023.X * from 2024.X through 2024.4.x

NVD description · AI analysis pending
7.5
group max
<1%
  • otrs otrs
CVE-2024-23790
+2 in the same advisory: …23791 …23792
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes.

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

NVD description · AI analysis pending
9.8
group max
<1%
  • otrs otrs
CVE-2023-6254
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.

NVD description · AI analysis pending
7.5<1%
  • otrs otrs
CVE-2023-5422
+2 in the same advisory: …5421 …38059
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication.

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

NVD description · AI analysis pending
9.1
group max
<1%
  • otrs otrs
CVE-2023-38060
+2 in the same advisory: …38056 …38058
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface mo

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the ContentType header of the attachment. This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

NVD description · AI analysis pending
8.8
group max
<1%
  • otrs otrs
CVE-2023-38057
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

NVD description · AI analysis pending
5.4<1%
  • otrs survey
CVE-2023-2534
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain li

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.

NVD description · AI analysis pending
8.1<1%
  • otrs otrs
CVE-2018-17883
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12.

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

NVD description · AI analysis pending
6.1<1%
  • otrs otrs
CVE-2023-1250
+1 in the same advisory: …1248
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code.

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

NVD description · AI analysis pending
7.8
group max
<1%
  • otrs otrs
CVE-2022-4427
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects

Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

NVD description · AI analysis pending
9.8<1%
  • otrs otrs
CVE-2022-3501
+1 in the same advisory: …39052
Article template contents with sensitive data could be accessed from agents without permissions.

Article template contents with sensitive data could be accessed from agents without permissions.

NVD description · AI analysis pending
7.5
group max
<1%
  • otrs otrs
CVE-2022-39051
+2 in the same advisory: …39049 …39050
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

NVD description · AI analysis pending
8.8
group max
<1%
  • otrs otrs
CVE-2022-32741
+1 in the same advisory: …32740
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

NVD description · AI analysis pending
5.3<1%
  • otrs otrs
CVE-2022-32739
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS release number.

When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS release number.

NVD description · AI analysis pending
5.3<1%
  • otrs calendar resource planning
  • otrs otrs
CVE-2021-36100
+2 in the same advisory: …0475 …1004
Specially crafted string in OTRS system configuration can allow the execution of any system command.

Specially crafted string in OTRS system configuration can allow the execution of any system command.

NVD description · AI analysis pending
8.8
group max
1%
  • otrs otrs
  • otrs otrs itsm
  • otrs otrs storm
CVE-2022-0474
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each r

Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.

NVD description · AI analysis pending
3.5<1%
  • otrs custom contact fields
CVE-2022-0473
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check.

OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.31 and prior versions.

NVD description · AI analysis pending
4.8<1%
  • otrs otrs
CVE-2021-36097
Agents are able to lock the ticket without the "Owner" permission.

Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

NVD description · AI analysis pending
4.3<1%
  • otrs otrs
CVE-2021-36094
+3 in the same advisory: …36093 …36095 …36096
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack.

It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

NVD description · AI analysis pending
5.4
group max
<1%
  • otrs otrs
CVE-2021-21440
+3 in the same advisory: …36092 …21443 …36091
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden.

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

NVD description · AI analysis pending
6.5
group max
<1%
  • otrs otrs
CVE-2021-21442
In the project create screen it's possible to inject malicious JS code to the certain fields.

In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.

NVD description · AI analysis pending
5.4<1%
  • otrs time accounting