CVE-2012-4600
Summary
| CVE | CVE-2012-4600 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-31 14:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.13 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.15 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs | 3.1.9 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#511404 - Open Technology Real Services nested tags cross-site scripting vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Exploit, US Government Resource |
| Support, Consulting, Development and Training for OTRS - Znuny GmbH | af854a3a-2127-422b-91ae-364da2661108 | znuny.com | |
| Security Advisory 2012-02 | OTRS | af854a3a-2127-422b-91ae-364da2661108 | www.otrs.com | Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support, Consulting, Development and Training for OTRS - Znuny GmbH | MITRE | znuny.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690345 Free Berkeley Software Distribution (FreeBSD) Security Update for otrs (d60199df-7fb3-11e2-9c5a-000d601460a4)