CVE-2025-31501
28.05.2025, 18:15
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
Vendor | Product | Version |
---|---|---|
bestpractical | request_tracker | 4.4.0 ≤ 𝑥 < 4.4.8 |
bestpractical | request_tracker | 5.0.0 ≤ 𝑥 < 5.0.8 |
𝑥
= Vulnerable software versions

Debian Releases