Unrated severityNVD Advisory· Published Aug 23, 2012· Updated Jun 16, 2026
CVE-2012-2582
CVE-2012-2582
Description
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element or (2) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
68cpe:2.3:a:otrs:otrs:2.4.0:beta1:*:*:*:*:*:*+ 47 more
- cpe:2.3:a:otrs:otrs:2.4.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.12:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs_itsm:2.1.0:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:otrs:otrs_itsm:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.1.5:*:*:*:*:*:*:*
- (no CPE)range: <3.1.6
- Range: <3.1.9
Patches
Vulnerability mechanics
References
5- www.kb.cert.org/vuls/id/582879nvdExploitUS Government Resource
- www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-01/nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2012-09/msg00024.htmlnvd
- secunia.com/advisories/50513nvd
- www.debian.org/security/2012/dsa-2536nvd
News mentions
0No linked articles in our index yet.