Vulnerabilities (CVE)

Filtered by vendor Bestpractical Subscribe
Filtered by product Request Tracker
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25802 1 Bestpractical 1 Request Tracker 2022-07-20 N/A 6.1 MEDIUM
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
CVE-2022-25803 1 Bestpractical 1 Request Tracker 2022-07-20 N/A 6.1 MEDIUM
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
CVE-2017-5361 1 Bestpractical 1 Request Tracker 2019-10-03 4.3 MEDIUM 5.9 MEDIUM
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.
CVE-2016-6127 1 Bestpractical 1 Request Tracker 2017-07-07 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.