Vulnerabilities > Bestpractical > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-14 | CVE-2022-25802 | Cross-site Scripting vulnerability in Bestpractical Request Tracker Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment. | 6.1 |
2022-07-14 | CVE-2022-25803 | Open Redirect vulnerability in Bestpractical Request Tracker Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search. | 6.1 |
2017-07-03 | CVE-2017-5361 | Unspecified vulnerability in Bestpractical Request Tracker Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack. | 5.9 |
2017-07-03 | CVE-2016-6127 | Cross-site Scripting vulnerability in Bestpractical Request Tracker Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type. | 6.1 |