c7b5d72b-886a-11e3-9533-60a44c524f57otrs -- multiple vulnerabilities

The OTRS Project reports:

SQL injection issue

An attacker that managed to take over the session of a logged in customer could create tickets and/or send follow-ups to existing tickets due to missing challenge token checks.

Discovery 2014-01-28
Entry 2014-01-28
Modified 2014-02-06
lt 3.1.19

gt 3.2.* lt 3.2.14

gt 3.3.* lt 3.3.4