CVE-2008-7275
OTRS <2.3.3 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.
Scores
EPSS
0.0021
EPSS Percentile
43.2%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
otrs/otrs
< 2.3.2
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
otrs/otrs
... and 35 more
Timeline
Published
Mar 18, 2011
Tracked Since
Feb 18, 2026