CVE-2012-2582
Summary
| CVE | CVE-2012-2582 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-23 10:32:14 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element or (2) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2012:1105-2: moderate: otrs: fixed security issue | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2536-1 otrs2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory 2012-01 | OTRS | af854a3a-2127-422b-91ae-364da2661108 | www.otrs.com | Vendor Advisory |
| Security Advisory SA50513 - SUSE update for otrs - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Vulnerability Note VU#582879 - Open Technology Real Services cross-site scripting vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Exploit, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.