OTRS Improper Privilege Management Vulnerability in Generic Interface Module

Vulnerability

A vulnerability allowing improper privilege management has been identified in the OTRS Generic Interface module. This issue allows users with read-only permissions to change the status of tickets. The vulnerability affects multiple OTRS versions, including 7.0.X, 8.0.X, 2023.X, 2024.X, and the Community Edition 6.0.x. Additionally, products based on the OTRS Community Edition are likely affected.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in ticket status, allowing users to manipulate workflow and potentially disrupt service management processes.

Remediation

Users are advised to update to OTRS version 2025.1.x. Note that there will be no patches for OTRS 7.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.