CVE-2011-1008: Medium severity best practical solutions request tracker vulnerability
ScripsOverlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1008?
CVE-2011-1008 is classified as a moderate severity vulnerability.
How do I fix CVE-2011-1008?
To fix CVE-2011-1008, upgrade to RT version 3.8.9 or later.
What software is affected by CVE-2011-1008?
CVE-2011-1008 affects several versions of Best Practical's RT, specifically versions prior to 3.8.9.
What type of vulnerability is CVE-2011-1008?
CVE-2011-1008 is an access control vulnerability that can allow unauthorized information access.
What are the symptoms of CVE-2011-1008 exploitation?
Exploitation of CVE-2011-1008 may lead to unauthorized access to sensitive ticket information for authenticated users.