DescriptionOpen Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
otrs2 (PTS)buster/non-free6.0.16-2fixed
bullseye/non-free, sid/non-free6.0.30-1fixed
stretch/non-free (security), stretch/non-free5.0.16-1+deb9u6vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


[stretch] - otrs2 <no-dsa> (Non-free not supported)
Only the 4.x and 5.x series are affected (and possibly earlier versions).
Add workaround and mark first 6.x version as fixing version

Search for package or bug name: Reporting problems