CVE-2012-4751
Summary
| CVE | CVE-2012-4751 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-22 16:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with whitespace before a javascript: URL in the SRC attribute of an element, as demonstrated by an IFRAME element. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.13 | All | All | All |
| Application | Otrs | Otrs | 2.4.14 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.15 | All | All | All |
| Application | Otrs | Otrs | 3.0.16 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.10 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs | 3.1.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory 2012-03 | OTRS | af854a3a-2127-422b-91ae-364da2661108 | www.otrs.com | Vendor Advisory |
| VU#603276 - OTRS contains a cross-site scripting vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| OTRS 3.1 Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | |
| OTRS Email Body CVE-2012-4751 HTML Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Support, Consulting, Development and Training for OTRS - Znuny GmbH | af854a3a-2127-422b-91ae-364da2661108 | znuny.com | |
| openSUSE-SU-2013:0145-1: moderate: update for otrs | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | znuny.com | Exploit |
| Support, Consulting, Development and Training for OTRS - Znuny GmbH | MITRE | znuny.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.