Show filters
62 Total Results
Displaying 1-10 of 62
Sort by:
Attacker Value
Unknown

CVE-2023-45024

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
Attacker Value
Unknown

CVE-2023-41260

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
Attacker Value
Unknown

CVE-2023-41259

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
Attacker Value
Unknown

CVE-2022-25803

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
Attacker Value
Unknown

CVE-2022-25802

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
Attacker Value
Unknown

CVE-2022-25801

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
Attacker Value
Unknown

CVE-2022-25800

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
Attacker Value
Unknown

CVE-2021-38562

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
Attacker Value
Unknown

CVE-2018-18898

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
Attacker Value
Unknown

CVE-2017-5943

Disclosure Date: July 03, 2017 (last updated November 26, 2024)
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL.
0