CVE-2017-14635: Otrs

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.

Affected products

  • Otrs Otrs: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; version 3.3.5 only; …

Published 2017-09-21. Last modified 2026-06-17.