CVE-2022-25802
14.07.2022, 12:15
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
Vendor | Product | Version |
---|---|---|
bestpractical | request_tracker | 𝑥 < 4.4.6 |
bestpractical | request_tracker | 5.0.0 ≤ 𝑥 < 5.0.3 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
request-tracker4 |
| ||||||||||||
request-tracker5 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
request-tracker4 |
| ||||||||||||||||||||
request-tracker5 |
|
References