CVE-2012-4600
OTRS 3.1 - Persistent Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.
Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en Open System Request Ticket (OTRS) Help Desk v2.4.x antes de v2.4.14, v3.0.x antes de v3.0.16, y v3.1.x antes de v3.1.10, cuando se usa Firefox u Opera, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un cuerpo de mensaje de correo electrónico con etiquetas HTML anidadas.
OTRS Open Technology Real Services versions 3.1.8 and 3.1.9 suffer from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-08-22 CVE Reserved
- 2012-08-31 CVE Published
- 2012-08-31 First Exploit
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/50615 | Third Party Advisory | |
http://znuny.com/en/#%21/advisory/ZSA-2012-02 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/22070 | 2012-10-18 | |
https://www.exploit-db.com/exploits/20959 | 2012-08-31 | |
http://www.kb.cert.org/vuls/id/511404 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.otrs.com/de/open-source/community-news/security-advisories/security-advisory-2012-02 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.0 Search vendor "Otrs" for product "Otrs" and version "2.4.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.0 Search vendor "Otrs" for product "Otrs" and version "2.4.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.0 Search vendor "Otrs" for product "Otrs" and version "2.4.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.0 Search vendor "Otrs" for product "Otrs" and version "2.4.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.0 Search vendor "Otrs" for product "Otrs" and version "2.4.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.0 Search vendor "Otrs" for product "Otrs" and version "2.4.0" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.1 Search vendor "Otrs" for product "Otrs" and version "2.4.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.2 Search vendor "Otrs" for product "Otrs" and version "2.4.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.3 Search vendor "Otrs" for product "Otrs" and version "2.4.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.4 Search vendor "Otrs" for product "Otrs" and version "2.4.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.5 Search vendor "Otrs" for product "Otrs" and version "2.4.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.6 Search vendor "Otrs" for product "Otrs" and version "2.4.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.7 Search vendor "Otrs" for product "Otrs" and version "2.4.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.8 Search vendor "Otrs" for product "Otrs" and version "2.4.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.9 Search vendor "Otrs" for product "Otrs" and version "2.4.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.10 Search vendor "Otrs" for product "Otrs" and version "2.4.10" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.11 Search vendor "Otrs" for product "Otrs" and version "2.4.11" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.12 Search vendor "Otrs" for product "Otrs" and version "2.4.12" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.4.13 Search vendor "Otrs" for product "Otrs" and version "2.4.13" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.0 Search vendor "Otrs" for product "Otrs" and version "3.0.0" | beta7 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.1 Search vendor "Otrs" for product "Otrs" and version "3.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.2 Search vendor "Otrs" for product "Otrs" and version "3.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.3 Search vendor "Otrs" for product "Otrs" and version "3.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.4 Search vendor "Otrs" for product "Otrs" and version "3.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.5 Search vendor "Otrs" for product "Otrs" and version "3.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.6 Search vendor "Otrs" for product "Otrs" and version "3.0.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.7 Search vendor "Otrs" for product "Otrs" and version "3.0.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.8 Search vendor "Otrs" for product "Otrs" and version "3.0.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.9 Search vendor "Otrs" for product "Otrs" and version "3.0.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.10 Search vendor "Otrs" for product "Otrs" and version "3.0.10" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.11 Search vendor "Otrs" for product "Otrs" and version "3.0.11" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.12 Search vendor "Otrs" for product "Otrs" and version "3.0.12" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.13 Search vendor "Otrs" for product "Otrs" and version "3.0.13" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.14 Search vendor "Otrs" for product "Otrs" and version "3.0.14" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.0.15 Search vendor "Otrs" for product "Otrs" and version "3.0.15" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.0 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.1 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.2 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.3 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.4 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.5 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Itsm Search vendor "Otrs" for product "Otrs Itsm" | 3.0.6 Search vendor "Otrs" for product "Otrs Itsm" and version "3.0.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.0 Search vendor "Otrs" for product "Otrs" and version "3.1.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.1 Search vendor "Otrs" for product "Otrs" and version "3.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.2 Search vendor "Otrs" for product "Otrs" and version "3.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.3 Search vendor "Otrs" for product "Otrs" and version "3.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.4 Search vendor "Otrs" for product "Otrs" and version "3.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.5 Search vendor "Otrs" for product "Otrs" and version "3.1.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.6 Search vendor "Otrs" for product "Otrs" and version "3.1.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.7 Search vendor "Otrs" for product "Otrs" and version "3.1.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.8 Search vendor "Otrs" for product "Otrs" and version "3.1.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.1.9 Search vendor "Otrs" for product "Otrs" and version "3.1.9" | - |
Affected
|