VYPR
Unrated severityNVD Advisory· Published Feb 4, 2014· Updated Apr 29, 2026

CVE-2014-1471

CVE-2014-1471

Description

SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allows remote attackers to execute arbitrary SQL commands via vectors related to a ticket search URL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

46
  • OTRS/Otrs46 versions
    cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*+ 45 more
    • cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.16:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.3:*:*:*:*:*:*:*
    • (no CPE)range: >=3.1.0, <3.1.19 || >=3.2.0, <3.2.14 || >=3.3.0, <3.3.4

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.