OTRS是德国OTRS公司的一个服务管理解决方案。 OTRS 7.0.X版本、8.0.X版本、2023.X版本、2024.X版本、2025.X版本和2026.X版本至2026.4.X之前版本存在安全漏洞,该漏洞源于工单文章渲染中活动SVG内容中和不当,可能导致攻击者通过邮件内容注入特制SVG有效载荷,在打开受影响工单时导致浏览器端资源耗尽和拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.x |
affected |
| OTRS AG | OTRS | 7.0.x |
affected |
8.0.x |
affected | ||
2023.x |
affected | ||
2024.x |
affected | ||
2025.x |
affected | ||
2026.x≤ 2026.3.x |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | OTRS | 7.0.x | - |
|
| OTRS AG | ((OTRS)) Community Edition | 6.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48188 | 9.1 CRITICAL | SQL Injection via MySQL Quote Method |
| CVE-2026-48209 | 7.1 HIGH | Reflected XSS in authenticated agent context |
| CVE-2026-48187 | 5.7 MEDIUM | Email with special content can lead to DoS |
| CVE-2026-48189 | 5.7 MEDIUM | Bypass DedicatedAgentToCustomerGroups Setting |
| CVE-2026-48191 | 3.5 LOW | Wrong Permission Handling in Document Search Article Meta Filters |
| CVE-2026-48190 | 3.5 LOW | Incorrect handling of permissions in External Interface Config Item List module |
No comments yet