First published: Fri Aug 14 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Request Tracker | <=4.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5475 has a severity rating of high due to the potential for remote code execution via XSS attacks.
To fix CVE-2015-5475, upgrade Request Tracker to version 4.2.12 or later.
CVE-2015-5475 allows remote attackers to execute arbitrary scripts in the context of user sessions.
Request Tracker versions 4.2.11 and earlier are affected by CVE-2015-5475.
You can detect vulnerability to CVE-2015-5475 by checking the version of Request Tracker you have installed.