CVE-2022-25802
14.07.2022, 12:15
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
| Vendor | Product | Version |
|---|---|---|
| bestpractical | request_tracker | 𝑥 < 4.4.6 |
| bestpractical | request_tracker | 5.0.0 ≤ 𝑥 < 5.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| request-tracker4 |
| ||||||||||||
| request-tracker5 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| request-tracker4 |
| ||||||||||||||||||||
| request-tracker5 |
|
References