CVE-2020-1779: Otrs Ticket Forms

Medium severity, CVSS 4.9. EPSS: 1% chance of exploitation in the next 30 days.

When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal sensitive information. This issue affects: OTRS AG OTRSTicketForms 6.0.x version 6.0.40 and prior versions; 7.0.x version 7.0.29 and prior versions; 8.0.x version 8.0.3 and prior versions.

Affected products

  • Otrs Ticket Forms: from 6.0.0, up to and including 6.0.40; from 7.0.0, up to and including 7.0.29; from 8.0.0, up to and including 8.0.3

Published 2021-02-08. Last modified 2026-06-17.