VYPR
Unrated severityNVD Advisory· Published Apr 18, 2011· Updated Apr 29, 2026

CVE-2011-1518

CVE-2011-1518

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.4.x before 2.4.10 and 3.x before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple XSS vulnerabilities in OTRS 2.4.x before 2.4.10 and 3.x before 3.0.7 allow remote attackers to inject arbitrary web script or HTML.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in Open Ticket Request System (OTRS) versions 2.4.x prior to 2.4.10 and 3.x prior to 3.0.7. The official description indicates that the attack vectors are unspecified, meaning the exact input parameters or interfaces that allow injection are not publicly detailed. Any vulnerable OTRS installation running these affected versions is potentially exposed [1].

Exploitation

An attacker can exploit these vulnerabilities remotely without requiring authentication, as the description does not mention any prerequisite credentials or network access restrictions. By crafting malicious input that is not properly sanitized by OTRS, the attacker can inject arbitrary web script or HTML. The exploitation does require either a direct request to a vulnerable page or tricking an authenticated user into interacting with a crafted link, depending on the specific but undisclosed vector. The concrete sequence of steps is not documented in publicly available references beyond the advisory notification [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript or HTML in the context of the affected OTRS instance. This can lead to session hijacking, theft of sensitive data, unauthorized ticket operations, or defacement of the OTRS interface. The impact is confined to the web application trust boundaries and may affect the confidentiality, integrity, and availability of the service depending on the attacker's actions.

Mitigation

The vulnerabilities are fixed in OTRS versions 2.4.10 and 3.0.7, as announced in the official advisory OSA-2011-01-en [1]. Administrators should upgrade to these or later versions immediately. No workarounds have been published for unpatched installations. The software is currently maintained, and no end-of-life declaration has been made for these branches at the time of the advisory.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

29
  • OTRS/Otrs29 versions
    cpe:2.3:a:otrs:otrs:2.4.0:beta1:*:*:*:*:*:*+ 28 more
    • cpe:2.3:a:otrs:otrs:2.4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.4.9:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.0.6:*:*:*:*:*:*:*
    • (no CPE)range: 2.4.x before 2.4.10, 3.x before 3.0.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.