PT-2026-45265 · Unknown · Otrs Community Edition
William Bastos
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-48209
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS Community Edition versions 6.x and earlier
OTRS Community Edition versions 7.0.x
Description
Improper neutralization of user-controllable input in ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS), which is a technique where malicious scripts are injected into a trusted website and reflected back to the user. By injecting malicious JavaScript into manipulated request URLs via crafted request parameters associated with ticket actions, attackers can execute arbitrary script code within the context of an authenticated agent session when the crafted link is opened.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Otrs Community Edition