CVE-2013-5587: XSS
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5587?
CVE-2013-5587 has a moderate severity level due to its ability to allow remote attackers to execute cross-site scripting attacks.
How do I fix CVE-2013-5587?
To fix CVE-2013-5587, upgrade Request Tracker to version 4.0.13 or later.
What versions of Request Tracker are affected by CVE-2013-5587?
CVE-2013-5587 affects Request Tracker versions 4.0.0 through 4.0.12.
Can I exploit CVE-2013-5587 without authentication?
Yes, CVE-2013-5587 can be exploited by remote attackers without authentication if the MakeClicky feature is configured.
What type of vulnerability is CVE-2013-5587 classified as?
CVE-2013-5587 is classified as a cross-site scripting (XSS) vulnerability.