Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
4.4.0 (semver) before 4.4.8
affected
5.0.0 (semver) before 5.0.8
affected
Description
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
4.4.0 (semver) before 4.4.8
5.0.0 (semver) before 5.0.8
References
lists.debian.org/debian-lts-announce/2025/05/msg00009.html
docs.bestpractical.com/release-notes/rt/index.html
docs.bestpractical.com/release-notes/rt/5.0.8
docs.bestpractical.com/release-notes/rt/4.4.8