
CVE-2025-30087 – Debian Security Advisory 5909-1
https://notcve.org/view.php?id=CVE-2025-30087
05 May 2025 — Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL. Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. • https://docs.bestpractical.com/release-notes/rt/4.4.8 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-31500 – Debian Security Advisory 5909-1
https://notcve.org/view.php?id=CVE-2025-31500
05 May 2025 — Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. • https://docs.bestpractical.com/release-notes/rt/5.0.8 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-31501 – Debian Security Advisory 5909-1
https://notcve.org/view.php?id=CVE-2025-31501
05 May 2025 — Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. • https://docs.bestpractical.com/release-notes/rt/5.0.8 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-1474
https://notcve.org/view.php?id=CVE-2014-1474
15 Jul 2014 — Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of service (CPU consumption) via a string without an address. Vulnerabilidad en la complejidad algorítmica en Email::Address::List anterior a 0.02, utilizado en RT 4.2.0 hasta 4.2.2, permite a atacantes remotos causar una denegación de servicio (consumo de CPU) a través de una cadena sin dirección. • http://blog.bestpractical.com/2014/01/security-vulnerability-in-rt-42.html • CWE-189: Numeric Errors •

CVE-2013-3736
https://notcve.org/view.php?id=CVE-2013-3736
05 May 2014 — Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file. Vulnerabilidad de XSS en la extensión MobileUI (también conocido como RT-Extension-MobileUI) anterior a 1.04 en Request Tracker (RT) 4.0.0 anterior a 4.0.13 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través del nombre de un archivo adjunt... • http://lists.bestpractical.com/pipermail/rt-announce/2013-June/000230.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5587
https://notcve.org/view.php?id=CVE-2013-5587
23 Aug 2013 — Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions. Vulnerabilidad Cross-site scripting (XSS) en Request Tracker (RT) v4.x anterior a v4.0.13, cuando se configura MakeClicky, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través una URL e... • http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-4733 – Debian Security Advisory 2671-1
https://notcve.org/view.php?id=CVE-2012-4733
23 May 2013 — Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors. Request Tracker (RT) v4.x anterior a v4.0.13 no aplica adecuadamente el permiso DeleteTicket y "la transición del ciclo de vida personalizado", lo que permite a usuarios remotos autenticados con el permiso ModifyTicket suprimir entradas a través de vectores no especif... • http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html • CWE-255: Credentials Management Errors •

CVE-2013-3368 – Debian Security Advisory 2671-1
https://notcve.org/view.php?id=CVE-2013-3368
23 May 2013 — bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name. bin/rt en Request Tracker (RT) v3.8.x anterior a v3.8.17 y v4.0.x anterior a v4.0.13 permite a los usuarios locales sobreescribir archivos arbitrarios a través de un ataque de enlaces simbólicos en un archivo temporal con nombre predecible. Multiple vulnerabilities have been discovered in Request Tracker, an extensible trou... • http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2013-3369 – Debian Security Advisory 2671-1
https://notcve.org/view.php?id=CVE-2013-3369
23 May 2013 — Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary private components via unspecified vectors. Request Tracker (RT) v3.8.x anterior a v3.8.17 y v4.0.x anterior a v4.0.13 permite a los usuarios remotos autenticados con los permisos para ver las páginas de administración para ejecutar a su elección los componentes privados a través de vectores no especificados. Multiple vulnerabilities ha... • http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html •

CVE-2013-3370 – Debian Security Advisory 2671-1
https://notcve.org/view.php?id=CVE-2013-3370
23 May 2013 — Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remote attackers to have an unspecified impact via a direct request. Request Tracker (RT) v3.8.x anterior a v3.8.17 y v4.0.x anterior a v4.0.13 no restringe adecuadamente el acceso a los componentes de devolución de llamada privados, lo que permite a atacantes remotos tienen un impacto no especificado a través de una petición directa. Multiple vulnerabilities have b... • http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html • CWE-264: Permissions, Privileges, and Access Controls •