CVE-2014-1471: Otrs

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allows remote attackers to execute arbitrary SQL commands via vectors related to a ticket search URL.

Affected products

  • Otrs Otrs: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.2.0 only; version 3.2.1 only; …

Published 2014-02-04. Last modified 2026-06-17.