Bestpractical Rt vulnerabilities
48 known vulnerabilities affecting bestpractical/rt.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM38LOW5
Vulnerabilities
Page 3 of 3
CVE-2011-4459P4LOWCVSS 3.5v3.0.0v3.0.1+81 more2012-06-04
CVE-2011-4459 [LOW] CWE-264 CVE-2011-4459: Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups,
Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a group membership.
nvd
CVE-2009-3892P4MEDIUMCVSS 4.3v3.4.6v3.6.0+13 more2009-11-17
CVE-2009-3892 [MEDIUM] CWE-79 CVE-2009-3892: Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x be
Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and other 3.4.6 through 3.8.4 versions allows remote attackers to inject arbitrary web script or HTML via certain Custom Fields.
nvd
CVE-2012-4730P4LOWCVSS 3.5v3.8.0v3.8.1+22 more2012-11-11
CVE-2012-4730 [LOW] CWE-264 CVE-2012-4730: Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users wi
Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and conduct phishing attacks or obtain sensitive information via unknown vectors.
nvd
CVE-2011-1687P4MEDIUMCVSS 4.0v3.0.0v3.0.1+45 more2011-04-22
CVE-2011-1687 [MEDIUM] CWE-200 CVE-2011-1687: Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7
Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote authenticated users to obtain sensitive information by using the search interface, as demonstrated by retrieving encrypted passwords.
nvd
CVE-2013-5587P4LOWCVSS 2.6v4.0.0v4.0.1+11 more2013-08-23
CVE-2013-5587 [LOW] CVE-2013-5587: Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
nvd
CVE-2008-3502P4MEDIUMCVSS 4.0v3.0.0v3.0.1+30 more2008-08-06
CVE-2008-3502 [MEDIUM] CVE-2008-3502: Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authentic
Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authenticated users to cause a denial of service (CPU or memory consumption) via unspecified vectors related to the Devel::StackTrace module for Perl.
nvd
CVE-2013-3368P4LOWCVSS 3.3v4.0.0v4.0.1+28 more2013-08-23
CVE-2013-3368 [LOW] CWE-59 CVE-2013-3368: bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to ove
bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.
nvd
CVE-2011-1007P4LOWCVSS 2.1≤ 3.8.9v1.0.0+70 more2011-02-28
CVE-2011-1007 [LOW] CWE-255 CVE-2011-1007: Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, whi
Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.
nvd
← Previous3 / 3