CVE-2012-4600
Summary
| CVE | CVE-2012-4600 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-31 14:55:00 UTC |
| Updated | 2023-11-07 02:11:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.13 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.15 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs | 3.1.9 | All | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.13 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.15 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs | 3.1.9 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.6 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory 2012-02 | OTRS | CONFIRM | www.otrs.com | Vendor Advisory |
| Support, Consulting, Development and Training for OTRS - Znuny GmbH | MISC | znuny.com | |
| Security Alerts - Secunia | SECUNIA | secunia.com | |
| Vulnerability Note VU#511404 - Open Technology Real Services nested tags cross-site scripting vulnerability | CERT-VN | www.kb.cert.org | Exploit, US Government Resource |
| Support, Consulting, Development and Training for OTRS - Znuny GmbH | znuny.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690345 Free Berkeley Software Distribution (FreeBSD) Security Update for otrs (d60199df-7fb3-11e2-9c5a-000d601460a4)