Specially crafted string in OTRS system configuration can allow the execution of any system command.
| Software | From | Fixed in |
|---|---|---|
| otrs / otrs_itsm | 8.0.0 | 8.0.28 |
| otrs / otrs_storm | - | 8.0.12 |
| otrs / otrs | 7.0.30 | 7.0.33 |
| otrs / otrs | 8.0.0 | 8.0.21 |
| otrs / otrs | - | 7.0.28 |
| otrs / otrs_itsm | - | 7.0.19 |