Home
LOW: 2.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:NDefault status
unaffected
Any version before 4.4.9
affected
5.0 (custom) before 5.0.9
affected
6.0 (custom) before 6.0.2
affected
Description
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
Problem types
CWE-1236 Improper Neutralization of Formula Elements in a CSV File
Product status
Any version before 4.4.9
5.0 (custom) before 5.0.9
6.0 (custom) before 6.0.2
References
docs.bestpractical.com/release-notes/rt/index.html