Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-3262
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.
0
Attacker Value
Unknown
CVE-2023-45024
Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
0
Attacker Value
Unknown
CVE-2023-41260
Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
0
Attacker Value
Unknown
CVE-2023-41259
Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
0
Attacker Value
Unknown
CVE-2022-25803
Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
0
Attacker Value
Unknown
CVE-2022-25802
Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
0
Attacker Value
Unknown
CVE-2022-25801
Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
0
Attacker Value
Unknown
CVE-2022-25800
Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
0
Attacker Value
Unknown
CVE-2021-38562
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
0