VYPR
Unrated severityNVD Advisory· Published Apr 2, 2014· Updated May 6, 2026

CVE-2014-2553

CVE-2014-2553

Description

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to dynamic fields.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OTRS 3.1.x, 3.2.x, and 3.3.x before specific patch releases allow authenticated users to inject arbitrary web script or HTML via dynamic fields.

Vulnerability

Open Ticket Request System (OTRS) versions 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 contain a cross-site scripting (XSS) vulnerability. The issue exists in the handling of dynamic fields, where user-supplied input is not properly sanitized before being rendered in the browser [1].

Exploitation

A remote attacker must first be authenticated to the OTRS system. The attacker then crafts input containing malicious web script or HTML within dynamic fields. When a victim (e.g., another agent) views the affected ticket or data, the injected script executes in the context of the OTRS interface [1].

Impact

Successful exploitation allows the attacker to inject arbitrary web script or HTML into the victim's browser session. This can lead to information disclosure, session hijacking, or further actions impersonating the victim. The scope is limited to actions within the OTRS application [1].

Mitigation

The vulnerability is fixed in OTRS 3.1.21, 3.2.16, and 3.3.6. Users should upgrade to these or later versions. No workarounds are mentioned in the disclosed references. The product is no longer supported by the vendor, so users on unsupported branches should migrate to a supported version [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

56
  • OTRS/Otrs55 versions
    cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*+ 54 more
    • cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.16:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.19:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.20:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.12:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.13:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.14:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.15:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:3.3.5:*:*:*:*:*:*:*
    • (no CPE)range: 3.1.x < 3.1.21, 3.2.x < 3.2.16, 3.3.x < 3.3.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.