First published: Fri Feb 28 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, and 3.3.x before 3.3.5 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML email.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | =3.3.0 | |
OTRS | =3.3.0-beta1 | |
OTRS | =3.3.0-beta2 | |
OTRS | =3.3.0-beta3 | |
OTRS | =3.3.0-beta4 | |
OTRS | =3.3.0-beta5 | |
OTRS | =3.3.0-rc1 | |
OTRS | =3.3.1 | |
OTRS | =3.3.2 | |
OTRS | =3.3.3 | |
OTRS | =3.3.4 | |
OTRS | =3.2.0 | |
OTRS | =3.2.0-beta1 | |
OTRS | =3.2.0-beta2 | |
OTRS | =3.2.0-beta3 | |
OTRS | =3.2.0-beta4 | |
OTRS | =3.2.0-beta5 | |
OTRS | =3.2.0-rc1 | |
OTRS | =3.2.1 | |
OTRS | =3.2.2 | |
OTRS | =3.2.3 | |
OTRS | =3.2.4 | |
OTRS | =3.2.5 | |
OTRS | =3.2.6 | |
OTRS | =3.2.7 | |
OTRS | =3.2.8 | |
OTRS | =3.2.9 | |
OTRS | =3.2.10 | |
OTRS | =3.2.14 | |
OTRS | =3.1.0 | |
OTRS | =3.1.1 | |
OTRS | =3.1.2 | |
OTRS | =3.1.3 | |
OTRS | =3.1.4 | |
OTRS | =3.1.5 | |
OTRS | =3.1.6 | |
OTRS | =3.1.7 | |
OTRS | =3.1.8 | |
OTRS | =3.1.9 | |
OTRS | =3.1.10 | |
OTRS | =3.1.11 | |
OTRS | =3.1.13 | |
OTRS | =3.1.14 | |
OTRS | =3.1.15 | |
OTRS | =3.1.16 | |
OTRS | =3.1.17 | |
OTRS | =3.1.18 | |
OTRS | =3.1.19 | |
=3.3.0 | ||
=3.3.0-beta1 | ||
=3.3.0-beta2 | ||
=3.3.0-beta3 | ||
=3.3.0-beta4 | ||
=3.3.0-beta5 | ||
=3.3.0-rc1 | ||
=3.3.1 | ||
=3.3.2 | ||
=3.3.3 | ||
=3.3.4 | ||
=3.2.0 | ||
=3.2.0-beta1 | ||
=3.2.0-beta2 | ||
=3.2.0-beta3 | ||
=3.2.0-beta4 | ||
=3.2.0-beta5 | ||
=3.2.0-rc1 | ||
=3.2.1 | ||
=3.2.2 | ||
=3.2.3 | ||
=3.2.4 | ||
=3.2.5 | ||
=3.2.6 | ||
=3.2.7 | ||
=3.2.8 | ||
=3.2.9 | ||
=3.2.10 | ||
=3.2.14 | ||
=3.1.0 | ||
=3.1.1 | ||
=3.1.2 | ||
=3.1.3 | ||
=3.1.4 | ||
=3.1.5 | ||
=3.1.6 | ||
=3.1.7 | ||
=3.1.8 | ||
=3.1.9 | ||
=3.1.10 | ||
=3.1.11 | ||
=3.1.13 | ||
=3.1.14 | ||
=3.1.15 | ||
=3.1.16 | ||
=3.1.17 | ||
=3.1.18 | ||
=3.1.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1695 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-1695, you should upgrade to OTRS versions 3.1.20, 3.2.15, or 3.3.5 and later, which include the necessary security patches.
CVE-2014-1695 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts or HTML.
CVE-2014-1695 affects OTRS versions 3.1.x prior to 3.1.20, 3.2.x prior to 3.2.15, and 3.3.x prior to 3.3.5.
Yes, CVE-2014-1695 can be exploited remotely, allowing attackers to inject malicious scripts through crafted HTML emails.