CVE-2019-9751: Otrs

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to Kernel/Output/Template/Document.pm.

Affected products

  • Otrs Otrs: from 6.0.0, before 6.0.17 (fixed in 6.0.17); from 7.0.0, before 7.0.5 (fixed in 7.0.5)

Published 2019-03-13. Last modified 2026-06-17.