CVE-2018-14593: Debian Linux

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Otrs Open Ticket Request System: from 4.0.0, up to and including 4.0.30; from 5.0.0, up to and including 5.0.28; from 6.0.0, up to and including 6.0.9

Published 2018-08-04. Last modified 2026-06-17.