OTRS
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*
- ~7.0
- ~8.0
- ~2023
- ~2024
- ~2025
- ~2026
A vulnerability allowing unauthenticated SQL injection has been identified in the database layer module of OTRS and OTRS Community Edition. This improper input validation issue can lead to authentication bypass, but only if the MySQL or MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X prior to 2026.4.X, as well as OTRS Community Edition version 6.0.x. Additionally, products based on OTRS Community Edition are likely affected.
Exploitation of this vulnerability allows for SQL injection, which can be used to bypass authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.