CVE-2013-3551: Otrs
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
Affected products
- Otrs Otrs: from 3.0.0, before 3.0.20 (fixed in 3.0.20); from 3.1.0, before 3.1.16 (fixed in 3.1.16); from 3.2.0, before 3.2.7 (fixed in 3.2.7)
- Otrs Otrs Itsm: from 3.0.0, before 3.0.8 (fixed in 3.0.8); from 3.1.0, before 3.1.9 (fixed in 3.1.9); from 3.2.0, before 3.2.5 (fixed in 3.2.5)
Published 2020-02-21. Last modified 2026-06-16.