CVE-2022-25802
Debian Security Advisory 5181-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
Best Practical Request Tracker (RT) versiones anteriores a 4.4.6 y versiones 5.x anteriores a 5.0.3 permite un ataque de tipo XSS por medio de un tipo de contenido diseƱado para un adjunto
It was discovered that Request Tracker was susceptible to timing attacks. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious attachments were supplied. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-23 CVE Reserved
- 2022-07-14 CVE Published
- 2024-08-03 CVE Updated
- 2025-08-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.bestpractical.com/release-notes/rt/4.4.6 | 2022-07-20 | |
https://docs.bestpractical.com/release-notes/rt/5.0.3 | 2022-07-20 |
URL | Date | SRC |
---|---|---|
https://docs.bestpractical.com/release-notes/rt/index.html | 2022-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bestpractical Search vendor "Bestpractical" | Request Tracker Search vendor "Bestpractical" for product "Request Tracker" | < 4.4.6 Search vendor "Bestpractical" for product "Request Tracker" and version " < 4.4.6" | - |
Affected
| ||||||
Bestpractical Search vendor "Bestpractical" | Request Tracker Search vendor "Bestpractical" for product "Request Tracker" | >= 5.0.0 < 5.0.3 Search vendor "Bestpractical" for product "Request Tracker" and version " >= 5.0.0 < 5.0.3" | - |
Affected
|