Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-3262

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.
0
Attacker Value
Unknown

CVE-2023-45024

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
Attacker Value
Unknown

CVE-2023-41260

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
Attacker Value
Unknown

CVE-2023-41259

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
Attacker Value
Unknown

CVE-2022-25803

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
Attacker Value
Unknown

CVE-2022-25802

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
Attacker Value
Unknown

CVE-2022-25801

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
Attacker Value
Unknown

CVE-2022-25800

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
Attacker Value
Unknown

CVE-2021-38562

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.