Unrated severityNVD Advisory· Published Aug 31, 2012· Updated Jun 16, 2026
CVE-2012-4600
CVE-2012-4600
Description
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
60cpe:2.3:a:otrs:otrs:2.4.0:beta1:*:*:*:*:*:*+ 50 more
- cpe:2.3:a:otrs:otrs:2.4.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.12:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.13:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:2.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs_itsm:3.0.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:otrs:otrs_itsm:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:otrs:otrs_itsm:3.0.6:*:*:*:*:*:*:*
- Range: <2.4.14, <3.0.16, <3.1.10
Patches
Vulnerability mechanics
References
4- www.kb.cert.org/vuls/id/511404nvdExploitUS Government Resource
- www.otrs.com/de/open-source/community-news/security-advisories/security-advisory-2012-02/nvdVendor Advisory
- secunia.com/advisories/50615nvd
- znuny.com/en/nvd
News mentions
0No linked articles in our index yet.