CVE-2018-19141: Debian Linux

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Otrs Open Ticket Request System: from 4.0.0, before 4.0.33 (fixed in 4.0.33); from 5.0.0, before 5.0.31 (fixed in 5.0.31)

Published 2018-11-11. Last modified 2026-06-17.