CVE-2023-1250: Otrs
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This issue affects OTRS: from 7.0.X before 7.0.42, from 8.0.X before 8.0.31; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Affected products
- Otrs Otrs: from 6.0.1, up to and including 6.0.34; from 7.0.0, before 7.0.42 (fixed in 7.0.42); from 8.0.0, before 8.0.31 (fixed in 8.0.31)
Published 2023-03-20. Last modified 2026-06-17.