Transmission · Transmission · CVE-2012-4037
**Name of the Vulnerable Software and Affected Versions**
Transmission versions prior to 2.61
**Description**
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the web client. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via specific fields in a torrent file, including the `comment`, `created by`, and `name` fields.
**Recommendations**
For versions prior to 2.61, update to version 2.61 or later to resolve the issue.