CVE-2012-4600

OTRS Help Desk <2.4.14-3.0.16-3.1.10 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-4600.

AI-analyzed exploit summary This Python script demonstrates a stored XSS vulnerability in OTRS 3.1.8 and 3.1.9 by sending an email with a malicious payload that bypasses input validation. The payload uses obfuscated script tags to execute arbitrary JavaScript in the context of the victim's browser.

Description

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags.

Exploits (2)

exploitdb WORKING POC
pythonwebappswindows
https://www.exploit-db.com/exploits/20959

This Python script demonstrates a stored XSS vulnerability in OTRS 3.1.8 and 3.1.9 by sending an email with a malicious payload that bypasses input validation. The payload uses obfuscated script tags to execute arbitrary JavaScript in the context of the victim's browser.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: OTRS 3.1.8 and 3.1.9
Auth required
Prerequisites: SMTP server access · Valid credentials for sending email
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
pythonwebappswindows
https://www.exploit-db.com/exploits/22070

This Python script demonstrates a stored XSS vulnerability in OTRS by sending an email with a malicious iframe payload. The exploit leverages the HTML email rendering feature to execute arbitrary JavaScript in the context of the victim's browser.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: OTRS 3.1.8, 3.1.9, 3.1.10
Auth required
Prerequisites: SMTP server access · valid credentials for email authentication
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/511404
Vendor Advisory x_refsource_misc
http://znuny.com/en/#%21/advisory/ZSA-2012-02
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50615

Scores

EPSS 0.0635
EPSS Percentile 92.7%

Details

CWE
CWE-79
Status published
Products (39)
otrs/otrs 2.4.0 beta1 (6 CPE variants)
otrs/otrs 2.4.1
otrs/otrs 2.4.2
otrs/otrs 2.4.3
otrs/otrs 2.4.4
otrs/otrs 2.4.5
otrs/otrs 2.4.6
otrs/otrs 2.4.7
otrs/otrs 2.4.8
otrs/otrs 2.4.9
... and 29 more
Published Aug 31, 2012
Tracked Since Feb 18, 2026