Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OTRS AG — Vulnerabilities & Security Advisories 81

Browse all 81 CVE security advisories affecting OTRS AG. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OTRS AG develops open-source IT service management software, primarily functioning as a ticketing system for enterprise support and incident tracking. The platform’s extensive feature set and long market presence have resulted in a significant historical vulnerability footprint, with 73 Common Vulnerabilities and Exposures currently recorded. Analysis of these flaws reveals a pattern of critical security weaknesses, most notably Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which often stem from insufficient input validation in legacy modules. Additionally, several instances of privilege escalation have been documented, allowing unauthorized users to gain administrative control. While the vendor has implemented regular patching cycles to address these issues, the high volume of past exploits highlights the complexity of securing a mature, feature-rich application. Organizations deploying this solution must prioritize rigorous patch management and strict access controls to mitigate the residual risks associated with its extensive attack surface.

CVE ID Title CVSS Severity Published
CVE-2023-38058 Tickets can be moved without permissions — OTRS CWE-269 4.1 Medium 2023-07-24
CVE-2023-38057 XSS stored in survey answers — OTRS CWE-20 4.1 Medium 2023-07-24
CVE-2023-38056 Code execution via System Configuration — OTRS CWE-78 7.2 High 2023-07-24
CVE-2023-2534 Information disclouse and DoS via websocket push events — OTRS CWE-285 7.6 High 2023-05-08
CVE-2023-1250 Code execution through ACL creation — OTRS CWE-20 7.4 High 2023-03-20
CVE-2023-1248 Possible XSS in Ticket Actions — OTRS CWE-79 6.1 Medium 2023-03-20
CVE-2022-4427 SQL Injection via OTRS Search API — OTRS CWE-20 6.5 Medium 2022-12-19
CVE-2022-39052 DoS attack using email — OTRS CWE-835 7.5 High 2022-10-17
CVE-2022-39051 Perl Code execution in Template Toolkit — OTRS CWE-913 6.8 Medium 2022-09-05
CVE-2022-39050 Possible XSS stored in customer information — OTRS CWE-79 4.6 Medium 2022-09-05
CVE-2022-39049 Possible XSS in Admin Interface — OTRS CWE-79 3.5 Low 2022-09-05
CVE-2022-32741 Information disclosure in Request New Password feature — OTRS CWE-200 5.3 Medium 2022-06-13
CVE-2022-32740 Information disclosure in the External Interface — OTRS CWE-200 3.5 Low 2022-06-13
CVE-2022-32739 OTRS version number is always in the exported ICS files — OTRS CWE-200 3.5 Low 2022-06-13
CVE-2022-1004 Information disclosure in the External Interface — OTRS CWE-200 4.3 Medium 2022-03-21
CVE-2022-0475 Possible XSS attack via translation — OTRS CWE-79 3.5 Low 2022-03-21
CVE-2021-36100 Authenticated remote code execution — OTRS 6.4 Medium 2022-03-21
CVE-2022-0474 Disclosure of mail addresses — OTRSCustomContactFields CWE-200 2.4 Low 2022-02-07
CVE-2022-0473 Dynamic field error message is vulnerable to XSS — OTRS CWE-79 3.8 Low 2022-02-07
CVE-2021-36097 Agents are able to lock the ticket without the "Owner" permission — OTRS CWE-266 3.5 Low 2021-10-18
CVE-2021-36096 Support Bundle includes S/Mime and PGP secret or PIN — ((OTRS)) Community Edition CWE-200 5.2 Medium 2021-09-06
CVE-2021-36095 User enumeration issue using "lost password" feature — ((OTRS)) Community Edition CWE-200 5.3 Medium 2021-09-06
CVE-2021-36094 XSS attack in appointment edit popup screen — ((OTRS)) Community Edition CWE-79 5.7 Medium 2021-09-06
CVE-2021-36093 DoS attack using PostMaster filters — ((OTRS)) Community Edition CWE-185 5.3 Medium 2021-09-06
CVE-2021-36092 XSS attack using special link in email — ((OTRS)) Community Edition CWE-79 6.5 Medium 2021-07-26
CVE-2021-36091 Unautorized access to the calendar appointments — ((OTRS)) Community Edition CWE-200 3.5 Low 2021-07-26
CVE-2021-21443 Unautorized listing of the customer user emails — ((OTRS)) Community Edition CWE-200 3.5 Low 2021-07-26
CVE-2021-21442 XSS vulnerability in Time Accounting — Time Accounting CWE-79 4.5 Medium 2021-07-26
CVE-2021-21440 Support Bundle includes S/Mime and PGP keys — ((OTRS)) Community Edition CWE-200 5.2 Medium 2021-07-26
CVE-2021-21441 XSS in the ticket overview screens — ((OTRS)) Community Edition CWE-79 7.5 High 2021-06-16

This page lists every published CVE security advisory associated with OTRS AG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.