cbcvebase.
CVE-2012-4733
published 2013-08-23

CVE-2012-4733: Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote…

PriorityP430medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.63%
73.3th percentile
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

Affected

8 ranges
VendorProductVersion rangeFixed in
bestpracticalrt
bestpracticalrt
bestpracticalrt
bestpracticalrt
bestpracticalrt
bestpracticalrt
bestpracticalrt
debianrequest-tracker4< request-tracker4 4.0.12-2 (bookworm)request-tracker4 4.0.12-2 (bookworm)

CVSS provenance

nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.