CVE-2015-6506: XSS
Published Sep 3, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.
Affected Software
1 affected component
bestpractical Request Tracker<=4.2.11
Remediation
Patch Available
Event History
Sep 3, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6506?
CVE-2015-6506 has been classified as a moderate severity XSS vulnerability that can allow remote attackers to inject malicious scripts.
2
How do I fix CVE-2015-6506?
To fix CVE-2015-6506, upgrade Request Tracker to version 4.2.12 or later.
3
What versions of Request Tracker are affected by CVE-2015-6506?
CVE-2015-6506 affects all versions of Request Tracker prior to 4.2.12.
4
What type of vulnerability is CVE-2015-6506?
CVE-2015-6506 is a cross-site scripting (XSS) vulnerability found in the cryptography interface of Request Tracker.
5
Can CVE-2015-6506 allow data theft?
Yes, CVE-2015-6506 could potentially allow attackers to perform actions on behalf of users or steal sensitive data through script injection.