Unrated severityNVD Advisory· Published Mar 1, 2014· Updated Jun 17, 2026
CVE-2014-1695
CVE-2014-1695
Description
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML email.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
50cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*+ 48 more
- cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.14:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.16:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.17:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.18:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.19:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.4:*:*:*:*:*:*:*
- (no CPE)range: 3.1.x < 3.1.20, 3.2.x < 3.2.15, 3.3.x < 3.3.5
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/131654/OTRS-3.x-Cross-Site-Scripting.htmlnvdExploit
- www.exploit-db.com/exploits/36842/nvdExploit
- secunia.com/advisories/57018nvdVendor Advisory
- www.otrs.com/security-advisory-2014-03-xss-issuenvdVendor Advisory
- adamziaja.com/poc/201401-xss-otrs.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-03/msg00030.htmlnvd
- www.osvdb.org/103781nvd
- www.securityfocus.com/bid/65844nvd
News mentions
0No linked articles in our index yet.