CVE-2013-3372Cross-site Scripting in Request-tracker4

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 34.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 17

Description

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

debiandebian/request-tracker4< request-tracker4 4.0.12-2 (bookworm)
NVDbestpractical/rt30 versions+29

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g7wx-g2c5-qxjv: Request Tracker (RT) 32022-05-17
OSV
CVE-2013-3372: Request Tracker (RT) 32013-08-23

📋Vendor Advisories

1
Debian
CVE-2013-3372: request-tracker4 - Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote a...2013
CVE-2013-3372 — Cross-site Scripting | cvebase