Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
2022-07-14T12:15:11.507
2024-11-21T06:53:01.680
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bestpractical | request_tracker | < 4.4.6 | Yes |
Application | bestpractical | request_tracker | < 5.0.3 | Yes |