Bestpractical

Request Tracker

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 20.07.2026 19:25:16
  • Zuletzt bearbeitet 07.08.2026 13:27:19

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can...

  • EPSS 0.25%
  • Veröffentlicht 20.07.2026 19:20:43
  • Zuletzt bearbeitet 07.08.2026 13:25:18

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-adminis...

  • EPSS 0.14%
  • Veröffentlicht 20.07.2026 19:18:25
  • Zuletzt bearbeitet 18.08.2026 18:55:02

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an a...

  • EPSS 0.15%
  • Veröffentlicht 20.07.2026 17:34:28
  • Zuletzt bearbeitet 07.08.2026 13:26:31

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An auth...

  • EPSS 0.16%
  • Veröffentlicht 20.07.2026 17:32:48
  • Zuletzt bearbeitet 07.08.2026 13:25:56

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL...

  • EPSS 0.24%
  • Veröffentlicht 21.05.2026 11:49:07
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vu...

  • EPSS 0.2%
  • Veröffentlicht 16.01.2026 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

  • EPSS 0.41%
  • Veröffentlicht 24.10.2025 06:15:35
  • Zuletzt bearbeitet 08.10.2026 11:10:00

The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enab...

  • EPSS 0.22%
  • Veröffentlicht 28.05.2025 00:00:00
  • Zuletzt bearbeitet 09.06.2025 18:59:03

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

  • EPSS 0.22%
  • Veröffentlicht 28.05.2025 00:00:00
  • Zuletzt bearbeitet 09.06.2025 18:58:52

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.