Vulnerabilities > CVE-2022-25801 - Server-Side Request Forgery (SSRF) vulnerability in Bestpractical Request Tracker for Incident Response

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
bestpractical
CWE-918
critical

Summary

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

Common Weakness Enumeration (CWE)