CVE-2015-5475: XSS
Published Aug 14, 2015
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
Affected Software
1 affected component
bestpractical Request Tracker<=4.2.11
Remediation
Patch Available
Event History
Aug 14, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5475?
CVE-2015-5475 has a severity rating of high due to the potential for remote code execution via XSS attacks.
2
How do I fix CVE-2015-5475?
To fix CVE-2015-5475, upgrade Request Tracker to version 4.2.12 or later.
3
What are the potential impacts of CVE-2015-5475?
CVE-2015-5475 allows remote attackers to execute arbitrary scripts in the context of user sessions.
4
Which versions of Request Tracker are affected by CVE-2015-5475?
Request Tracker versions 4.2.11 and earlier are affected by CVE-2015-5475.
5
How can I detect if my system is vulnerable to CVE-2015-5475?
You can detect vulnerability to CVE-2015-5475 by checking the version of Request Tracker you have installed.