OTRS
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*
- ~7.0
- ~8.0
- ~2023
- ~2024
- ~2025
- ~2026
A vulnerability in the OTRS Customer Backend module has been identified, allowing improper input validation that could lead to unauthorized access to customer information restricted from certain groups. This issue affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, and 2026.X prior to 2026.4.X. The vulnerability is only applicable if the feature is enabled and CustomerGroupSupport is utilized.
Exploitation of this vulnerability could result in unauthorized access to customer information, violating data access restrictions between groups.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.