CVE-2014-2553
Description
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to dynamic fields.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OTRS 3.1.x, 3.2.x, and 3.3.x before specific patch releases allow authenticated users to inject arbitrary web script or HTML via dynamic fields.
Vulnerability
Open Ticket Request System (OTRS) versions 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 contain a cross-site scripting (XSS) vulnerability. The issue exists in the handling of dynamic fields, where user-supplied input is not properly sanitized before being rendered in the browser [1].
Exploitation
A remote attacker must first be authenticated to the OTRS system. The attacker then crafts input containing malicious web script or HTML within dynamic fields. When a victim (e.g., another agent) views the affected ticket or data, the injected script executes in the context of the OTRS interface [1].
Impact
Successful exploitation allows the attacker to inject arbitrary web script or HTML into the victim's browser session. This can lead to information disclosure, session hijacking, or further actions impersonating the victim. The scope is limited to actions within the OTRS application [1].
Mitigation
The vulnerability is fixed in OTRS 3.1.21, 3.2.16, and 3.3.6. Users should upgrade to these or later versions. No workarounds are mentioned in the disclosed references. The product is no longer supported by the vendor, so users on unsupported branches should migrate to a supported version [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
56cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*+ 54 more
- cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.14:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.16:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.17:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.18:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.19:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.20:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.15:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.3.5:*:*:*:*:*:*:*
- (no CPE)range: 3.1.x < 3.1.21, 3.2.x < 3.2.16, 3.3.x < 3.3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- secunia.com/advisories/57616nvdVendor Advisory
- www.otrs.com/security-advisory-2014-04-xss-issuenvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2014-04/msg00062.htmlnvd
News mentions
0No linked articles in our index yet.