NA

CVE-2022-25802

Published: 14/07/2022 Updated: 20/07/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Best Practical Request Tracker (RT) prior to 4.4.6 and 5.x prior to 5.0.3 allows XSS via a crafted content type for an attachment.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bestpractical request tracker

Vendor Advisories

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system CVE-2022-25802 It was discovered that Request Tracker is vulnerable to a cross-site scripting (XSS) attack when displaying attachment content with fraudulent content types Additionally it was discovered that Request Tracker did ...