First published: Fri Aug 31 2012(Updated: )
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | =2.4.0-beta1 | |
OTRS | =2.4.0-beta2 | |
OTRS | =2.4.0-beta3 | |
OTRS | =2.4.0-beta4 | |
OTRS | =2.4.0-beta5 | |
OTRS | =2.4.0-beta6 | |
OTRS | =2.4.1 | |
OTRS | =2.4.2 | |
OTRS | =2.4.3 | |
OTRS | =2.4.4 | |
OTRS | =2.4.5 | |
OTRS | =2.4.6 | |
OTRS | =2.4.7 | |
OTRS | =2.4.8 | |
OTRS | =2.4.9 | |
OTRS | =2.4.10 | |
OTRS | =2.4.11 | |
OTRS | =2.4.12 | |
OTRS | =2.4.13 | |
OTRS | =3.0.0-beta1 | |
OTRS | =3.0.0-beta2 | |
OTRS | =3.0.0-beta3 | |
OTRS | =3.0.0-beta4 | |
OTRS | =3.0.0-beta5 | |
OTRS | =3.0.0-beta6 | |
OTRS | =3.0.0-beta7 | |
OTRS | =3.0.1 | |
OTRS | =3.0.2 | |
OTRS | =3.0.3 | |
OTRS | =3.0.4 | |
OTRS | =3.0.5 | |
OTRS | =3.0.6 | |
OTRS | =3.0.7 | |
OTRS | =3.0.8 | |
OTRS | =3.0.9 | |
OTRS | =3.0.10 | |
OTRS | =3.0.11 | |
OTRS | =3.0.12 | |
OTRS | =3.0.13 | |
OTRS | =3.0.14 | |
OTRS | =3.0.15 | |
OTRS | =3.0.0 | |
OTRS | =3.0.1 | |
OTRS | =3.0.2 | |
OTRS | =3.0.3 | |
OTRS | =3.0.4 | |
OTRS | =3.0.5 | |
OTRS | =3.0.6 | |
OTRS | =3.1.0 | |
OTRS | =3.1.1 | |
OTRS | =3.1.2 | |
OTRS | =3.1.3 | |
OTRS | =3.1.4 | |
OTRS | =3.1.5 | |
OTRS | =3.1.6 | |
OTRS | =3.1.7 | |
OTRS | =3.1.8 | |
OTRS | =3.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4600 has a medium severity level due to its ability to facilitate cross-site scripting attacks.
To fix CVE-2012-4600, upgrade your OTRS Help Desk software to version 2.4.14, 3.0.16, or 3.1.10 or later.
CVE-2012-4600 affects OTRS Help Desk versions 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10.
CVE-2012-4600 is classified as a medium severity vulnerability, not critical.
CVE-2012-4600 can be exploited by remote attackers using Firefox or Opera to inject arbitrary web scripts or HTML.