CVE-2008-7275

OTRS <2.3.3 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.

Scores

EPSS 0.0021
EPSS Percentile 43.2%

Classification

CWE
CWE-79
Status published

Affected Products (50)

otrs/otrs < 2.3.2
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
... and 35 more

Timeline

Published Mar 18, 2011
Tracked Since Feb 18, 2026