CVE-2012-2769
Description
Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page of the Extension::MobileUI extension for RT 3.8.x and RT before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page of the Extension::MobileUI extension for RT 3.8.x and RT before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Vulnerability
Multiple cross-site scripting (XSS) vulnerabilities exist in the topic administration page of the Extension::MobileUI extension for Best Practical Solutions RT 3.8.x and in RT before 4.0.6. The vulnerabilities allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Affected versions include Extension::MobileUI before 1.02 and RT before 4.0.6 [1].
Exploitation
An attacker can exploit these XSS vulnerabilities by sending crafted input to the topic administration page. No authentication or special privileges are mentioned as required; the attacker only needs to be able to submit data to the vulnerable page. The exact attack vector is not disclosed in the available references [1].
Impact
Successful exploitation allows an attacker to inject arbitrary web script or HTML, leading to potential information disclosure, session hijacking, or other client-side attacks. The attacker's injected script executes in the context of the victim's browser when they view the affected page [1].
Mitigation
Users should upgrade to Extension::MobileUI version 1.02 or later for RT 3.8.x, and to RT version 4.0.6 or later. The advisory notes that only installations with the vulnerable extension are affected; RT installations without the extension are not vulnerable [1]. No other workarounds are provided in the available references.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <4.0.6
- Range: <1.02
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.bestpractical.com/pipermail/rt-announce/2012-July/000208.htmlnvdPatchVendor Advisory
- secunia.com/advisories/50010nvdVendor Advisory
- www.securityfocus.com/bid/54684nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/77211nvd
News mentions
0No linked articles in our index yet.