CVE-2024-43443: Otrs AG Otrs

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

Affected products

  • Otrs AG Otrs: from 7.0, up to and including 7.0.50; from 8.0, before 8.1 (fixed in 8.1); from 2023, before 2024 (fixed in 2024); from 2024, before 2024.6 (fixed in 2024.6)
  • Otrs AG Otrs Community Edition: from 6.0, before 6.1 (fixed in 6.1)

Published 2024-08-26. Last modified 2026-06-17.