CVE-2012-2582: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element or (2) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.
Affected Software
Event History
Frequently Asked Questions
What are the impacts of CVE-2012-2582?
CVE-2012-2582 allows remote attackers to inject arbitrary web scripts into vulnerable OTRS applications, potentially compromising user data and session integrity.
How do I mitigate CVE-2012-2582?
To mitigate CVE-2012-2582, you should upgrade to OTRS versions 2.4.13 or later, 3.0.15 or later, or 3.1.9 or later.
Which OTRS versions are affected by CVE-2012-2582?
CVE-2012-2582 affects OTRS versions 2.4.x prior to 2.4.13, 3.0.x prior to 3.0.15, 3.1.x prior to 3.1.9, and OTRS ITSM 2.1.x and 3.0.x prior to specified versions.
Is CVE-2012-2582 a critical risk to OTRS users?
Yes, CVE-2012-2582 is considered a critical vulnerability due to its ability to allow XSS attacks.
What type of vulnerability is CVE-2012-2582 categorized as?
CVE-2012-2582 is categorized as a cross-site scripting (XSS) vulnerability.