4.3
CVSSv2

CVE-2015-5475

Published: 14/08/2015 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x prior to 4.2.12 allow remote malicious users to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.

Vulnerable Product Search on Vulmon Subscribe to Product

bestpractical request tracker

Vendor Advisories

It was discovered that Request Tracker, an extensible trouble-ticket tracking system is susceptible to a cross-site scripting attack via the user and group rights management pages (CVE-2015-5475) and via the cryptography interface, allowing an attacker with a carefully-crafted key to inject JavaScript into RT's user interface Installations which u ...