Otrs Faq vulnerabilities
4 known vulnerabilities affecting otrs/faq.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2021-21438MEDIUMCVSS 4.3≥ 6.0.0, < 6.0.292021-03-22
CVE-2021-21438 [MEDIUM] CWE-264 CVE-2021-21438: Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.
nvd
CVE-2013-2637MEDIUMCVSS 6.1PoCfixed in 2.0.8≥ 2.1.0, < 2.1.42020-02-12
CVE-2013-2637 [MEDIUM] CWE-79 CVE-2013-2637: A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
nvd
CVE-2013-2625MEDIUMCVSS 6.5≥ 2.0.0, < 2.0.8≥ 2.1.0, < 2.1.4+1 more2019-11-27
CVE-2013-2625 [MEDIUM] CWE-269 CVE-2013-2625: An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
nvd
CVE-2016-5843CRITICALCVSS 9.4v2.0.1v2.0.2+28 more2016-09-17
CVE-2016-5843 [CRITICAL] CWE-89 CVE-2016-5843: Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.
nvd