CVE-2019-9753: Otrs

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an agent or a customer user can use the search result screens to disclose information from invalid system entities. Following is the list of affected entities: Custom Pages, FAQ Articles, Service Catalogue Items, ITSM Configuration Items.

Affected products

  • Otrs Otrs: from 7.0.0, before 7.0.5 (fixed in 7.0.5)

Published 2019-06-03. Last modified 2026-06-17.