Loading...
Loading...
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3) CustomerTicketProcess.pm, and (4) CustomerTicketZoom.pm in Kernel/Modules/ in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allow remote attackers to hijack the authentication of arbitrary users for requests that (5) create tickets or (6) send follow-ups to existing tickets.
February 4, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-1694
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.