Open Ticket Request System (OTRS) 7.0.48

CPE Details

Open Ticket Request System (OTRS) 7.0.48
7.0.48
2024-02-03
00h39 +00:00
2024-02-03
00h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:otrs:otrs:7.0.48:*:*:*:*:*:*:*

Informations

Vendor

otrs

Product

otrs

Version

7.0.48

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-24387 2025-03-10 09h28 +00:00 A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.   This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.x
6.5
Medium
CVE-2024-23790 2024-01-29 09h21 +00:00 Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.
9.8
Critical
CVE-2024-23791 2024-01-29 09h21 +00:00 Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
7.5
High
CVE-2024-23792 2024-01-29 09h20 +00:00 When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
6.5
Medium
CVE-2020-1778 2020-11-23 15h32 +00:00 When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
4.3
Medium
CVE-2011-2385 2011-07-19 18h00 +00:00 The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors.
6.5